Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-5974

21
FAUCET Score

CVE-2017-5974 is a heap-based buffer overflow in the zziplib library (versions 0.13.56 through 0.13.62) that can be triggered by a crafted ZIP file, primarily affecting Debian-based systems. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction, and leading to a high impact on availability (denial of service). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low current threat level.

Impacted Technologies

VendorProductVersion(s)CPE
0.13.56CPE matchmatch criteria
cpe:2.3:a:gdraheim:zziplib:0.13.56:*:*:*:*:*:*:*
0.13.57CPE matchmatch criteria
cpe:2.3:a:gdraheim:zziplib:0.13.57:*:*:*:*:*:*:*
0.13.58CPE matchmatch criteria
cpe:2.3:a:gdraheim:zziplib:0.13.58:*:*:*:*:*:*:*
0.13.59CPE matchmatch criteria
cpe:2.3:a:gdraheim:zziplib:0.13.59:*:*:*:*:*:*:*
0.13.60CPE matchmatch criteria
cpe:2.3:a:gdraheim:zziplib:0.13.60:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.85%
Probability of exploitation in next 30 days
EPSS Percentile
76.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0185 is in the 87th percentile among its peer group of 5,760 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

microsoftpatch availablevia msrc
Product: 16914-17084Fixed in: 0.13.74-1
microsoftpatch availablevia msrc
Product: 16914-16817Fixed in: 0.13.74-1
microsoftpatch availablevia msrc
Product: azl3 zziplib 0.13.74-1 on Azure Linux 3.0Fixed in: 0.13.74-1
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: zziplib

Vendor Advisories (2)

microsoft2017-Mar/CVE-2017-5974Moderate

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

Mar 14, 2017
redhatCVE-2017-5974Low

zziplib: heap-based buffer overflow in __zzip_get32 (fetch.c)

Feb 9, 2017

References

blogs.gentoo.org / ago/2017/02/09/zziplib-heap-based-buffer-overflow-in-__zzip_get32-fetch-c
ExploitThird Party Advisory
debian.org / security/2017/dsa-3878
Third Party Advisory
openwall.com / lists/oss-security/2017/02/14/3
Mailing List
securityfocus.com / bid/96268
Third Party AdvisoryVDB Entry