Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 30: FEDORA-2019-d43282031d Moderate: SharpZipLib Directory Traversal

fedora
Calendar Grey May 27, 2019
Dist Fedora Esm H88
Update sharpziplib to version 1.1.0 to resolve the directory traversal security issue on Fedora 30.
upgrade to version 1.1.0 which fixes the vulnerability of directory traversal

Summary

SharpZipLib, formerly NZipLib is a Zip, GZip, Tar and BZip2 library

written entirely in C# . It is implemented as an assembly (installable

in the GAC), and thus can easily be incorporated into other projects.

upgrade to version 1.1.0 which fixes the vulnerability of directory traversal

* Fri Mar 1 2019 Timotheus Pokorra - 1.1.0-0

* Upgrade to v1.1.0

[ 1 ] Bug #1585949 - sharpziplib: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file [fedora-28]

https://bugzilla.redhat.com/show_bug.cgi?id=1585949

su -c 'dnf upgrade --advisory FEDORA-2019-d43282031d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 30
Version: 1.1.0
Release: 0.fc30
Summary: Zip, GZip, Tar and BZip2 library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here