[DSA 6439-1] zip security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6439-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
August 14, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : zip
CVE ID         : not yet available
Debian Bug     : 1143866

Harry Sintonen discovered that the Info-ZIP zip program is prone to a
command injection vulnerability if a specially crafted filename is
processed.

For the stable distribution (trixie), this problem has been fixed in
version 3.0-15+deb13u1.

We recommend that you upgrade your zip packages.

For the detailed security status of zip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/zip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmp+zQdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QVcBAAnd7x3SZhj3brsV9Hl4CBzKzkbuXBgRqVBs3wzPVZBLRS4gLfv0MQtfq+
J4t+MM61MllX2F1dZuQ4QPnSIMQfie9adjFZKWyv1srHdr+oBTN/TFxaCG9kZrTe
6xfWZAqja1U9EktisZPFG8lRZPxPRR6IL9SnohavGUzYhPPYAye4rBK9wHYpPjgV
vNgsQq+Rc7fJLnWLbzNswSI76NIGHQjddF2qBQ7ZrsQ2HMXMtgdpxLk92VoOY72m
jLCqANxgGJ9U7KDpJJfHO0Mx8XxD044i1O7ocdqRXevIxpcqcDUJRo6b5EXN5Myq
vS4CHVbC89AXhhXVvxU/VDNgSHBWWz28AdeS23Y2kvsu0u70Oy/nkaNugCgYgEu7
pylFqtynccS9usDdjJ1eC1gu1OJx2mlD5ilRLfGFi/ZxUCV6MgMfub962VOKFXOI
hdiJIAepjZak09xwJhP7LHYfPx0Tublnm3jTdwu9xeXcFHo9C522HV0WePSDuazu
3bmUQWEBITq8EOiMAX3r0qDMR61Z+D7BSu18QlGiI//bTylKFiIdyRVaOJgIbyLa
Z3TqdiFDztDtFkE2xb+PRopRK+x7PPDs7LwHkkSRB5PjUvHh8zcPqzSCTky+pu8K
iK5TDF0Ex/l5IlzLVuJY2NHxzpaUfPWQj94j+/IhVcmYTyEVsso=
=1vBn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.