Vulnerability Bulletins

DSA-3152 unzip - security update

   
Affected software Debian
 
A flaw was found in the test_compr_eb() function allowing out-of-boundsread and write access to memory locations. By carefully crafting acorrupt ZIP archive an attacker can trigger a heap overflow, resultingin application crash or possibly having other unspecified impact.

More info:

https://www.debian.org/security/2015/dsa-3152