Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 22: FEDORA-2015-4559 moderate: mingw-libzip integer overflow

fedora
Calendar Grey March 31, 2015
Scroller Fedora
This patch for Fedora 22 resolves the integer overflow vulnerability found in mingw-libzip, enhancing the security for managing ZIP files.
Security fix for CVE-2015-2331.

Summary

libzip is a C library for reading, creating, and modifying zip archives. Files

can be added from data buffers, files, or compressed data copied directly from

other zip archives. Changes made without closing the archive can be reverted.

The API is documented by man pages.

Update Information:

Security fix for CVE-2015-2331.

Change Log

References


[ 1 ] Bug #1204676 - CVE-2015-2331 php: libzip: integer overflow when processing ZIP archives https://bugzilla.redhat.com/show_bug.cgi?id=1204676

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update mingw-libzip' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: mingw-libzip
Product: Fedora 22
Version: 0.11.2
Release: 3.fc22
Summary: C library for reading, creating, and modifying zip archives

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.