Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian: DSA-3386-1 Critical: Unzip Code Exec And DoS Threat

debian
Calendar Grey October 31, 2015
Debian Logo
Debian Security Advisory DSA-3386-1 warns of critical unzip package vulnerabilities. Users should update the package to prevent unauthorized access and code execution.
Two vulnerabilities have been found in unzip, a de-archiver for .zip files

Summary

CVE-2015-7696

Gustavo Grieco discovered that unzip incorrectly handled certain
password protected archives. If a user or automated system were
tricked into processing a specially crafted zip archive, an attacker
could possibly execute arbitrary code.

CVE-2015-7697

Gustavo Grieco discovered that unzip incorrectly handled certain
malformed archives. If a user or automated system were tricked into
processing a specially crafted zip archive, an attacker could
possibly cause unzip to hang, resulting in a denial of service.

For the oldstable distribution (wheezy), these problems have been fixed
in version 6.0-8+deb7u4.

For the stable distribution (jessie), these problems have been fixed in
version 6.0-16+deb8u1.

For the testing distribution (stretch), these problems have been fixed
in version 6.0-19.

For the unstable distribution (sid), these problems have been fixed in
version 6.0-19.

We recommend that you upgrade your unzip packages.

Further information about Debian Securit...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: unzip
CVE ID: CVE-2015-7696 CVE-2015-7697

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here