Bug 45177

Summary: unzip: Denial of service (4.2)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Philipp Hahn <hahn>
Status: CLOSED FIXED QA Contact: Arvid Requate <requate>
Severity: normal    
Priority: P3 Flags: requate: Patch_Available+
Version: UCS 4.2   
Target Milestone: UCS 4.2-1-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional):
Max CVSS v3 score: 6.8 (CVSSv2:AV:N/AC:M/Au:N/C:P/I:P/A:P)
Bug Depends on: 37657    
Bug Blocks:    

Description Arvid Requate univentionstaff 2017-08-10 14:31:02 CEST
Package has been copied from the jessie Repos.

Advisory: ucs-4.2-1/doc/errata/staging/unzip.yaml
Comment 1 Arvid Requate univentionstaff 2017-08-10 16:28:12 CEST
I've moved the advisory to ucs-4.2-0/doc/errata/staging, because the package has been imported to ucs-4.2-0.
Comment 2 Arvid Requate univentionstaff 2017-08-16 18:52:32 CEST
I've moved the advisory back to ucs-4.2-1/doc/errata/staging as recommended by you. The announce tool relies on the "scope: " field in the advisory, which is correct.

I've added this bug number to the advisory.
Comment 3 Arvid Requate univentionstaff 2017-08-23 14:35:29 CEST
<http://errata.software-univention.de/ucs/4.2/142.html>