Double free vulnerability in the zipdirentread function in zipdirent.c in libzip allows attackers to have unspecified impact via unknown vectors.
{ "vanir_signatures": [ { "digest": { "length": 5237.0, "function_hash": "247741707400283749085108019441784905923" }, "signature_type": "Function", "id": "CVE-2017-12858-11de36c1", "signature_version": "v1", "target": { "file": "lib/zip_dirent.c", "function": "_zip_dirent_read" }, "source": "https://github.com/nih-at/libzip/commit/2217022b7d1142738656d891e00b3d2d9179b796", "deprecated": false }, { "digest": { "line_hashes": [ "126407887668340329650951841643656814806", "79489290485161336371396243068446216870", "103867276804264513481566455227706953226", "200745644596356662579889932048953027052", "18703439355701899585658934728937768609", "10360732491339512210894939584152610856" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2017-12858-f2d51449", "signature_version": "v1", "target": { "file": "lib/zip_dirent.c" }, "source": "https://github.com/nih-at/libzip/commit/2217022b7d1142738656d891e00b3d2d9179b796", "deprecated": false } ] }