Univention Bugzilla – Bug 47853
libarchive-zip-perl: Multiple issues (4.3)
Last modified: 2018-09-26 13:24:58 CEST
New Debian libarchive-zip-perl 1.59-1+deb9u1 fixes: This update addresses the following issue: * Prevent from traversing symlinks and parent directories when extracting (CVE-2018-10860)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/libarchive-zip-perl_1.59-1.dsc +++ apt/ucs_4.3-0-errata4.3-2/source/libarchive-zip-perl_1.59-1+deb9u1.dsc @@ -1,3 +1,15 @@ +1.59-1+deb9u1 [Fri, 21 Sep 2018 17:17:23 +0200] Salvatore Bonaccorso <carnil@debian.org>: + + * Non-maintainer upload by the Security Team. + * Prevent from traversing symlinks and parent directories when extracting + (CVE-2018-10860) (Closes: #902882) + * Extract test files needed for t/25_traversal.t test. + Add zip files to debian/t/data directory and add them to + debian/sorce/include-binaries to include those in the debian tarball. + Add an override for dh_auto_test to copy debian/t/data/*.zip testfiles + to test directory prior to running the testsuite. + Clean test files needed for t/25_traversal.t in dh_clean + 1.59-1 [Fri, 12 Aug 2016 22:13:05 +0200] Salvatore Bonaccorso <carnil@debian.org>: * Import upstream version 1.59 <http://10.200.17.11/4.3-2/#8108016107811789308>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.3-2] 0efe199208 Bug #47853: libarchive-zip-perl_1.59-1+deb9u1 doc/errata/staging/libarchive-zip-perl.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<http://errata.software-univention.de/ucs/4.3/240.html>