Univention Bugzilla – Bug 49365
unzip: Multiple issues (4.3)
Last modified: 2019-05-02 12:35:02 CEST
New Debian unzip 6.0-21+deb9u1 fixes: This update addresses the following issue: * Heap-based buffer overflow in fileio.c:UzpPassword function allows code execution (CVE-2018-1000035)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/unzip_6.0-21.dsc +++ apt/ucs_4.3-0-errata4.3-4/source/unzip_6.0-21+deb9u1.dsc @@ -1,3 +1,8 @@ +6.0-21+deb9u1 [Wed, 17 Apr 2019 21:23:40 +0200] Santiago Vila <sanvila@debian.org>: + + * Fix buffer overflow in password protected ZIP archives. Closes: #889838. + Patch borrowed from SUSE. For reference, this is CVE-2018-1000035. + 6.0-21 [Sun, 11 Dec 2016 21:03:30 +0100] Santiago Vila <sanvila@debian.org>: * Rename all debian/patches/* to have .patch ending. <http://10.200.17.11/4.3-4/#7920889309958969208>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.3-4] c82cbb378e Bug #49365: unzip 6.0-21+deb9u1 doc/errata/staging/unzip.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<http://errata.software-univention.de/ucs/4.3/491.html>