[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DSA 5202-1] unzip security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5202-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
August 08, 2022                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : unzip
CVE ID         : CVE-2022-0529 CVE-2022-0530
Debian Bug     : 1010355

Sandipan Roy discovered two vulnerabilities in InfoZIP's unzip program,
a de-archiver for .zip files, which could result in denial of service
or potentially the execution of arbitrary code.

For the stable distribution (bullseye), these problems have been fixed in
version 6.0-26+deb11u1.

We recommend that you upgrade your unzip packages.

For the detailed security status of unzip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/unzip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLxKt0ACgkQEMKTtsN8
TjYNMQ/+MhXS6UoQXN2E7m/fBr2vFUKuaqJqJoouTxOqOIOKmCkhxUoUOW10yihY
AEay4oucz0X5uBIFxeIEUnPmWKg0NJqv2T6PNgu1A0NmY67EN2bOTEBaH/s1VpmT
ZsaKTorDQQrJDvl/KqNESP+i+SnNxDzSo9ES+wvK/KffDBqgAYvvEaHXRKHSqll+
Vm3cWxeSG/JucpZsGXld+C/D3mmTH0MMNmP2GrZHCsGN4WutWwokbyaqw92lbtIn
8x3ll8T8M+5d7PiGASOUwR4z8G/2/SXO3QUuro/zZtaGA9G68jPS/+QwlumlV7tu
BLW0IiAN0TmZCJ+mqXQseqFy98GQ0JyUAFpv1CJfseBO49SAb2UMO3HWzovqhZqx
eaxX6lhfyF4sDthFaOjGlbBb9Afl35KEcThgCrbyNuaLT44J4hGjZk2MxVvnPXKl
8/I9t8K7Xbm81YF9i6mlQqLymiUPq2tXIN8o5fVt1/vupm9/HI2UVd2W8lKw/k8x
8uytMp9be3qmknTFL97jknmwD/5OWUQkm3Y4Swl3aVKSrTTymc2ZZPz3TE8EkWGf
elfh+6xSnHRqpBYN2TdhBt7iqAMWZ2q1eFbUTUbbUkOZKf9BblR74OBNNcHWGcik
jPmlF6WkKW6lEM0btX0poV+RbCW8CShMlS7IdTra0E8vDP6jnA4=
=0N2D
-----END PGP SIGNATURE-----


Reply to: