Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 22 FEDORA-2015-15858 Critical Unzip Heap Overflow

fedora
Calendar Grey September 22, 2015
Dist Fedora Esm H88
Important Fedora patch for unarchiver resolves memory overflow and endless loop vulnerabilities. Update promptly using dnf.
unzip-6.0-22.fc21 - Fix heap overflow and infinite loop when invalid input is given (#1260947) unzip-6.0-22.fc22 - Fix heap overflow and infinite loop when invalid input is given ...

Summary

The unzip utility is used to list, test, or extract files from a zip

archive. Zip archives are commonly found on MS-DOS systems. The zip

utility, included in the zip package, creates zip archives. Zip and

unzip are both compatible with archives created by PKWARE(R)'s PKZIP

for MS-DOS, but the programs' options and default behaviors do differ

in some respects.

Install the unzip package if you need to list, test or extract files from

a zip archive.

Update Information:

unzip-6.0-22.fc21 - Fix heap overflow and infinite loop when invalid input is given (#1260947) unzip-6.0-22.fc22 - Fix heap overflow and infinite loop when invalid input is given (#1260947) unzip-6.0-23.fc23 - Fix heap overflow and infinite loop when invalid input is given (#1260947)

Change Log

References


[ 1 ] Bug #1260944 - unzip: Heap overflow and DoS in 6.0 https://bugzilla.redhat.com/show_bug.cgi?id=1260944

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update unzip' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: unzip
Product: Fedora 22
Version: 6.0
Release: 22.fc22
URL:
Summary: A utility for unpacking zip files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here