Bug#773722: unzip: CVE-2014-8139 CVE-2014-8140 CVE-2014-8141

2014-12-22 Thread Salvatore Bonaccorso
Source: unzip Version: 6.0-4 Severity: grave Tags: security upstream Hi, the following vulnerabilities were published for unzip. (disclaimer I was not yet able to verify any of those, but oCert advisory claims to affect all unzip = 6.0). CVE-2014-8139[0]: CRC32 heap overflow CVE-2014-8140[1]:

Bug#773722: unzip: CVE-2014-8139 CVE-2014-8140 CVE-2014-8141

2014-12-22 Thread Santiago Vila
El 22/12/14 a las 17:29, Salvatore Bonaccorso escribió: Source: unzip Version: 6.0-4 Severity: grave Tags: security upstream Hi, the following vulnerabilities were published for unzip. (disclaimer I was not yet able to verify any of those, but oCert advisory claims to affect all unzip = 6.0).