• [SECURITY] [DSA 5202-1] unzip security update

    From Moritz Muehlenhoff@21:1/5 to All on Mon Aug 8 17:30:01 2022
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5202-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 08, 2022 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : unzip
    CVE ID : CVE-2022-0529 CVE-2022-0530
    Debian Bug : 1010355

    Sandipan Roy discovered two vulnerabilities in InfoZIP's unzip program,
    a de-archiver for .zip files, which could result in denial of service
    or potentially the execution of arbitrary code.

    For the stable distribution (bullseye), these problems have been fixed in version 6.0-26+deb11u1.

    We recommend that you upgrade your unzip packages.

    For the detailed security status of unzip please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/unzip

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLxKt0ACgkQEMKTtsN8 TjYNMQ/+MhXS6UoQXN2E7m/fBr2vFUKuaqJqJoouTxOqOIOKmCkhxUoUOW10yihY AEay4oucz0X5uBIFxeIEUnPmWKg0NJqv2T6PNgu1A0NmY67EN2bOTEBaH/s1VpmT ZsaKTorDQQrJDvl/KqNESP+i+SnNxDzSo9ES+wvK/KffDBqgAYvvEaHXRKHSqll+ Vm3cWxeSG/JucpZsGXld+C/D3mmTH0MMNmP2GrZHCsGN4WutWwokbyaqw92lbtIn 8x3ll8T8M+5d7PiGASOUwR4z8G/2/SXO3QUuro/zZtaGA9G68jPS/+QwlumlV7tu BLW0IiAN0TmZCJ+mqXQseqFy98GQ0JyUAFpv1CJfseBO49SAb2UMO3HWzovqhZqx eaxX6lhfyF4sDthFaOjGlbBb9Afl35KEcThgCrbyNuaLT44J4hGjZk2MxVvnPXKl 8/I9t8K7Xbm81YF9i6mlQqLymiUPq2tXIN8o5fVt1/vupm9/HI2UVd2W8lKw/k8x 8uytMp9be3qmknTFL97jknmwD/5OWUQkm3Y4Swl3aVKSrTTymc2ZZPz3TE8EkWGf elfh+6xSnHRqpBYN2TdhBt7iqAMWZ2q1eFbUTUbbUkOZKf9BblR74OBNNcHWGcik jPmlF6WkKW6lEM0btX0poV+RbCW8CShMlS7IdTra0E8vDP6jnA4=
    =0N2D
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)