Your message dated Fri, 07 Aug 2026 14:46:22 +0000
with message-id <[email protected]>
and subject line Bug#1143866: fixed in zip 3.0-16
has caused the Debian Bug report #1143866,
regarding zip: Command injection issue with zip
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143866: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143866
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: zip
Version: 3.0-15ubuntu3
Severity: normal
Tags: patch
I'm with the upstream Info-ZIP team. We've has a command injection issue
reported against zip that we've been able to reproduce with the latest Debian
sources.
Attached patch is the proposed fix. Ping me if you need more details on
reproduction steps
253.patch
Description: 253.patch
--- End Message ---
--- Begin Message ---
Source: zip
Source-Version: 3.0-16
Done: Santiago Vila <[email protected]>
We believe that the bug you reported is fixed in the latest version of
zip, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Santiago Vila <[email protected]> (supplier of updated zip package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 07 Aug 2026 16:15:00 +0200
Source: zip
Architecture: source
Version: 3.0-16
Distribution: unstable
Urgency: medium
Maintainer: Santiago Vila <[email protected]>
Changed-By: Santiago Vila <[email protected]>
Closes: 1143866
Changes:
zip (3.0-16) unstable; urgency=medium
.
* Stop prefixing patch filenames with numbers.
* Fix command injection issue. Closes: #1143866.
Reported upstream by Harry Sintonen <[email protected]>.
* Drop "Rules-Requires-Root: no" (default).
* Drop "Priority: optional" (default).
* Update standards-version.
* Disable redundant/duplicate Salsa CI jobs.
* Drop no longer needed lintian override.
Checksums-Sha1:
94ecc652935e41d8fbd7cdf6db3d33c926f15ee7 1439 zip_3.0-16.dsc
378f3f1606521bf9cdc23f2d86a3236de82009eb 12512 zip_3.0-16.debian.tar.xz
b9f9cc45436915031d9ea228c94f88507d64e32d 5462 zip_3.0-16_source.buildinfo
Checksums-Sha256:
3f7a651a5e38105d56c7c190c4c388308cbab0a5a2ae97a7804a2e9ae37aefe6 1439
zip_3.0-16.dsc
fa79a0226f00f487b290489f62e1cd7f4a338df529a1e413fea4d168b8eee8f7 12512
zip_3.0-16.debian.tar.xz
8fa44cfd57a8391e86d423c087eb09d715971255b1e344f5167ce75140e927ca 5462
zip_3.0-16_source.buildinfo
Files:
e85217c6658b2c3958c56da5109285bf 1439 utils optional zip_3.0-16.dsc
993361600c239ef537118603b66f819d 12512 utils optional zip_3.0-16.debian.tar.xz
af3f161247b3adf49a6df063b5ed7507 5462 utils optional
zip_3.0-16_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAmp16W8ACgkQQc5/C58b
izKlxwf/d0+Q14J0O3+9swYKJsCFcw26Mc8ZceSBj6HYxxPuU7oPGK1UJlgf8VcL
DT58+I8ARqw0yxT9R0eG+aygkWPtcJk/xgIgylLQlFgDeWiDr2bd/p20WQBn80wy
jD+FSIyBoy7LqNTNUQybJdWUTQqCykQ8/KLX5OR/S+aIKxudHlDLQ+DwoJxx7SIL
xjgNhRXIsXwhgE6jwzcyPPpKf0gMGpmkYQaqqNi4vflgsF/+e4zGQ6EEqb2TXMSJ
582Z57vaTestP4eUh73z8DBjI6A1RlQvWwtUM3pnSA+fBDguIftzZtf+5t+0HMiL
ZI29ykXrm+5dqPWHqUCFqbGTMt85VQ==
=KBDg
-----END PGP SIGNATURE-----
pgprXDFFf6fZP.pgp
Description: PGP signature
--- End Message ---