it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5202-1] unzip security update
- Date: Mon, 8 Aug 2022 15:26:24 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
- List-archive: https://lists.debian.org/msgid-search/20220808152624.GA7334 AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=Q56X9AC+ewHfoCfX/wurIaBr5xL8mfrtCj8jabjejqU=; b=An YUP+LZ0fIbEG8JJ3ZUsC/6bFaMs9LIVZ6HrgEcO3N0OcgyH237qPr+RC5iBE6tYYuymbXAlKXsfj/ nhw03g3KsiPEBlZl6V2LCUu4gl/3c8BVlKLvRoFuKWJqxgNwLZdYbO8qQZEXw349nG2hAcvqSgXFZ fpbC1U7/VhVxYq6hr4dFNiSAzBm6usvzuRoK8vlJae3JSzavszhnyyKUapfsdR+D6B4q87AJQ5rS6 vbrmEaNiCWEuXpN6KbAlBfWpn/JI9+1lhYYZRpl0NJRIMph+5xgrzvfBqVszm3OehciZ5u/bkWWQO NUnMKYL7RHqVEgd10l7E40xH7kD8TtGg==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Mon, 8 Aug 2022 15:26:49 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <Vjk4dIXOugP.A.ekB.5sS8iB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5202-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 08, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : unzip
CVE ID : CVE-2022-0529 CVE-2022-0530
Debian Bug : 1010355
Sandipan Roy discovered two vulnerabilities in InfoZIP's unzip program,
a de-archiver for .zip files, which could result in denial of service
or potentially the execution of arbitrary code.
For the stable distribution (bullseye), these problems have been fixed in
version 6.0-26+deb11u1.
We recommend that you upgrade your unzip packages.
For the detailed security status of unzip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/unzip
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLxKt0ACgkQEMKTtsN8
TjYNMQ/+MhXS6UoQXN2E7m/fBr2vFUKuaqJqJoouTxOqOIOKmCkhxUoUOW10yihY
AEay4oucz0X5uBIFxeIEUnPmWKg0NJqv2T6PNgu1A0NmY67EN2bOTEBaH/s1VpmT
ZsaKTorDQQrJDvl/KqNESP+i+SnNxDzSo9ES+wvK/KffDBqgAYvvEaHXRKHSqll+
Vm3cWxeSG/JucpZsGXld+C/D3mmTH0MMNmP2GrZHCsGN4WutWwokbyaqw92lbtIn
8x3ll8T8M+5d7PiGASOUwR4z8G/2/SXO3QUuro/zZtaGA9G68jPS/+QwlumlV7tu
BLW0IiAN0TmZCJ+mqXQseqFy98GQ0JyUAFpv1CJfseBO49SAb2UMO3HWzovqhZqx
eaxX6lhfyF4sDthFaOjGlbBb9Afl35KEcThgCrbyNuaLT44J4hGjZk2MxVvnPXKl
8/I9t8K7Xbm81YF9i6mlQqLymiUPq2tXIN8o5fVt1/vupm9/HI2UVd2W8lKw/k8x
8uytMp9be3qmknTFL97jknmwD/5OWUQkm3Y4Swl3aVKSrTTymc2ZZPz3TE8EkWGf
elfh+6xSnHRqpBYN2TdhBt7iqAMWZ2q1eFbUTUbbUkOZKf9BblR74OBNNcHWGcik
jPmlF6WkKW6lEM0btX0poV+RbCW8CShMlS7IdTra0E8vDP6jnA4=
=0N2D
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5202-1] unzip security update, Moritz Muehlenhoff, 08.08.2022
Archiv bereitgestellt durch MHonArc 2.6.24.