Vulnerability Bulletins

DSA-3113 unzip - security update

   
Affected software Debian
 
Michele Spagnuolo of the Google Security Team discovered that unzip, anextraction utility for archives compressed in .zip format, is affectedby heap-based buffer overflows within the CRC32 verification function(CVE-2014-8139), the test_compr_eb() function (CVE-2014-8140) and thegetZip64Data() function (CVE-2014-8141), which may lead to the executionof arbitrary code.

More info:

https://www.debian.org/security/2014/dsa-3113