Various CVE fixes, most importantly CVE-2025-11001 This also backports the Debian patch (PR unfortunately stalled upstream, with no communication from upstream developers) to not echo passwords when dealing with encrypted archives.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b6422d64f9 2025-11-27 00:46:38.116127+00:00 -------------------------------------------------------------------------------- Name : 7zip Product : Fedora 43 Version : 25.01 Release : 1.fc43 URL : https://7-zip.org Summary : A file archiver Description : 7-Zip is a file archiver with a high compression ratio. The main features of 7-Zip are: * High compression ratio in 7z format with LZMA and LZMA2 compression * Supported formats: * Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM * Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT, GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2, RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z. * For ZIP and GZIP formats, 7-Zip provides a compression ratio that is 2-10 % better than the ratio provided by PKZip and WinZip * Strong AES-256 encryption in 7z and ZIP formats * Powerful command line version -------------------------------------------------------------------------------- Update Information: Various CVE fixes, most importantly CVE-2025-11001 This also backports the Debian patch (PR unfortunately stalled upstream, with no communication from upstream developers) to not echo passwords when dealing with encrypted archives. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 26 2025 Michel Lind - 25.01-1 - Update to 25.01 - 25.00+ fixes CVE-2025-11001; Resolves: rhbz#2416011 - Backport Debian patch to disable echo-ing password; Resolves: rhbz#2412315 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2376517 - 7zip-25.01 is available https://bugzilla.redhat.com/show_bug.cgi?id=2376517 [ 2 ] Bug #2381822 - CVE-2025-53817 7zip: 7-Zip Null pointer array write [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2381822 [ 3 ] Bug #2381825 - CVE-2025-53816 7zip: 7-Zip heap buffer overflow [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2381825 [ 4 ] Bug #2387643 - CVE-2025-55188 7zip: 7-Zip Symbolic Link Extraction Vulnerability [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2387643 [ 5 ] Bug #2412315 - 7z echoes a supplied password https://bugzilla.redhat.com/show_bug.cgi?id=2412315 [ 6 ] Bug #2416899 - CVE-2025-11001 7zip: 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2416899 [ 7 ] Bug #2416900 - CVE-2025-11001 7zip: 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2416900 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b6422d64f9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to 1.26.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-8dc64f8f59 2024-02-15 01:41:57.775593 -------------------------------------------------------------------------------- Name : engrampa Product : Fedora 38 Version : 1.26.2 Release : 1.fc38 URL : https://mate-desktop.org/ Summary : MATE Desktop file archiver Description : Mate File Archiver is an application for creating and viewing archives files, such as zip, xv, bzip2, cab, rar and other compress formats. -------------------------------------------------------------------------------- Update Information: update to 1.26.2 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 6 2024 Wolfgang Ulbrich - 1.26.2-1 - update to 1.26.2 * Wed Jan 24 2024 Fedora Release Engineering - 1.26.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering - 1.26.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Wed Jul 19 2023 Fedora Release Engineering - 1.26.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild > > > > > > > c3bab3b (update to 1.26.1) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2262840 - TRIAGE CVE-2023-52138 engrampa: remote command execution via path traversal vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2262840 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-8dc64f8f59' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.