Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora Core 5: 2006-099 Moderate: Zip File Overflow Notice

fedora
Calendar Grey February 6, 2006
Dist Fedora Esm H88
The latest patch resolves multiple concerns within the extraction tool, addressing vulnerabilities linked to memory overflow, while also improving the security framework of Fedora Core 4.
This update fixes several vulnerabilities in the unzip utility.

Summary

The unzip utility is used to list, test, or extract files from a zip

archive. Zip archives are commonly found on MS-DOS systems. The zip

utility, included in the zip package, creates zip archives. Zip and

unzip are both compatible with archives created by PKWARE(R)'s PKZIP

for MS-DOS, but the programs' options and default behaviors do differ

in some respects.

Install the unzip package if you need to list, test or extract files from

a zip archive.

- fix bug 178961 - CVE-2005-4667 - unzip long file name buffer overflow

* Wed Aug 3 2005 Ivana Varekova 5.51-12.fc4

- fix bug 164928 - TOCTOU issue in unzip

* Mon May 9 2005 Ivana Varekova 5.51-11

- fix bug 156959 – invalid file mode on created files

0b621ba9565ce4507c6809e342dfdfea2cceec46 SRPMS/unzip-5.51-13.fc4.src.rpm

e8f67af74893566142d7c4a957fd1f6ca6aca209 ppc/unzip-5.51-13.fc4.ppc.rpm

268b5b2e62fdd4263b4849cac5d3ae915f5095d7 ppc/debug/unzip-debuginfo-5.51-13.fc4.ppc.rpm

5fe96c87893982f2752d0f528e1691591d8b655e x86_64/unzip-5.51-13.fc4.x86_64.rpm

47676a08bd382d976c08ea3927b51fd07cb67850 x86_64/debug/unzip-debuginfo-5.51-13.fc4.x86_64.rpm

69cf5c0e4faf82e7e5305abe5cf7feb8d480ba99 i386/unzip-5.51-13.fc4.i386.rpm

c7260e51f7b60ffbf92a99c44caa928e5cb50df6 i386/debug/unzip-debuginfo-5.51-13.fc4.i386.rpm

This update can be installed with the 'yum' update program. Use 'yum update

package-name' at the command line. For more information, refer to 'Managing

Software with yum,' available at .

fedora-announce-list mailing list

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Name: unzip
Version: 5.51
Release: 13.fc4
Summary: A utility for unpacking zip files.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here