MGASA-2019-0341 - Updated zipios++ packages fix security vulnerability

Publication date: 30 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0341.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-13453

Updated zipios++ packages fix security vulnerability:

Mike Salvatore discovered that Zipios mishandled certain malformed ZIP
files. An attacker could use this vulnerability to cause a denial of
service or consume system resources (CVE-2019-13453).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25282
- https://ubuntu.com/security/notices/USN-4057-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13453

SRPMS:
- 7/core/zipios++-0.1.5.9-6.1.mga7

Mageia 2019-0341: zipios++ security update

Updated zipios++ packages fix security vulnerability: Mike Salvatore discovered that Zipios mishandled certain malformed ZIP files

Summary

Updated zipios++ packages fix security vulnerability:
Mike Salvatore discovered that Zipios mishandled certain malformed ZIP files. An attacker could use this vulnerability to cause a denial of service or consume system resources (CVE-2019-13453).

References

- https://bugs.mageia.org/show_bug.cgi?id=25282

- https://ubuntu.com/security/notices/USN-4057-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13453

Resolution

MGASA-2019-0341 - Updated zipios++ packages fix security vulnerability

SRPMS

- 7/core/zipios++-0.1.5.9-6.1.mga7

Severity
Publication date: 30 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0341.html
Type: security
CVE: CVE-2019-13453

Related News