-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4741-1                [email protected]
https://www.debian.org/lts/security/                       Andrej Shadura
August 16, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : unzip
Version        : 6.0-26+deb11u2 6.0-28+deb12u1
CVE ID         : not yet available
Debian Bug     : 1142904 1142905 1142906

Akhil Koul discovered a vulnerability in the Info-ZIP unzip program,
which could result in the execution of arbitrary code if a specially
crafted file is processed.

For Debian 11 bullseye, this problem has been fixed in version
6.0-26+deb11u2.

For Debian 12 bookworm, this problem has been fixed in version
6.0-28+deb12u1.

In addition, both uploads contain patches that fix two crashes in unzip
caused by stack and heap out-of-bounds access.

We recommend that you upgrade your unzip packages.

For the detailed security status of unzip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/unzip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCaoHGigAKCRDoRGtKyMdy
YTfCAP9RAtY09iz/PP6ytdmtwVP1pgg1Hl+l2T7OrQ3yJBVInQEAlls3sZOcluya
GmgUk7H310yNaQpa1SwTfU39+omA/w4=
=3l+o
-----END PGP SIGNATURE-----

Reply via email to