[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 330-1] unzip security update



Package        : unzip
Version        : 6.0-4+deb6u3
CVE ID         : CVE-2015-7696 CVE-2015-7697
Debian Bug     : 802160 802162

Gustavo Grieco discovered with a fuzzer that unzip was vulnerable to a
heap overflow and to a denial of service with specially crafted
password-protected ZIP archives.

For the Debian 6 squeeze, these issues haven been fixed in unzip
6.0-4+deb6u3.

-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/

Attachment: signature.asc
Description: PGP signature


Reply to: