Bug 45177 - unzip: Denial of service (4.2)
unzip: Denial of service (4.2)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.2
Other Linux
: P3 normal (vote)
: UCS 4.2-1-errata
Assigned To: Philipp Hahn
Arvid Requate
:
Depends on: 37657
Blocks:
  Show dependency treegraph
 
Reported: 2017-08-10 14:31 CEST by Arvid Requate
Modified: 2017-08-31 12:41 CEST (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 6.8 (CVSSv2:AV:N/AC:M/Au:N/C:P/I:P/A:P)
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2017-08-10 14:31:02 CEST
Package has been copied from the jessie Repos.

Advisory: ucs-4.2-1/doc/errata/staging/unzip.yaml
Comment 1 Arvid Requate univentionstaff 2017-08-10 16:28:12 CEST
I've moved the advisory to ucs-4.2-0/doc/errata/staging, because the package has been imported to ucs-4.2-0.
Comment 2 Arvid Requate univentionstaff 2017-08-16 18:52:32 CEST
I've moved the advisory back to ucs-4.2-1/doc/errata/staging as recommended by you. The announce tool relies on the "scope: " field in the advisory, which is correct.

I've added this bug number to the advisory.
Comment 3 Arvid Requate univentionstaff 2017-08-23 14:35:29 CEST
<http://errata.software-univention.de/ucs/4.2/142.html>