This bug was fixed in the package unzip - 6.0-31ubuntu1

---------------
unzip (6.0-31ubuntu1) stonking; urgency=medium

  * Merge with Debian unstable (LP: #2163534). Remaining changes:
    - d/p/unzip60-alt-iconv-utf8.patch: add patch
      + Add patch from archlinux which adds the -O option, allowing a
        charset to be specified for the proper unzipping of non-Latin and
        non-Unicode filenames.
      + Added documentation for `-I` and `-O` options to unzip (man/unzip.1) and
        zipinfo (man/zipinfo.1) man pages (LP #138307).
      + Fixed garbled output when `zipinfo` or `unzip -Z` is called
        without arguments (LP #1429939).
    - d/t/*: add autopkgtests (LP #2023994)
    - d/p/fix-troff-warning.patch: removes monospace directives to fix
      troff warnings (LP #2054670)
    - d/p/fix-code-pages.patch: add patch
      + Fixed bit 11 of General purpose flag support on systems with UTF-8
      system charset (LP #2066389).
      + Fixed OEM code page being always assumed Russian/Cyrillic CP866 on
      any UTF-8 system.
      + Added proper OEM code page detection based on system locale setting.
      + Removed translation from ISO 8859-1 to local charset; assumption that
        any non-unicode archive uses it is for sure wrong as it can be any
        charset used on archive creator's local system; also do not treat
        PKZIP for UNIX 2.51 archives as having ISO 8859-1 charset for the
        same reasons.
      + Enabled UTF-8 output by default on Unix systems.
    - d/t/SmokeTests.py: add tests for unicode file names in different encodings
    - d/p/CVE-2021-4217.patch: add patch to fix null pointer dereference and
      use of uninitialized data.
  * Renamed patch files to drop leading numbers, to match upstream.

unzip (6.0-31) unstable; urgency=medium

  * Apply upstream fix for CAN-2026-2034442. Closes: #1142906.
    (heap buffer overflow WRITE in memextract() STORED path)

unzip (6.0-30) unstable; urgency=medium

  * Stop prefixing patch filenames with numbers.
  * Fix invalid DEP3 metadata.
  * Apply upstream fix for CAN-2026-2034440. Closes: #1142904.
    (heap out-of-bounds read in EF_IZUNIX3 extra field handler)
  * Apply upstream fix for CAN-2026-2034443. Closes: #1142905.
    (stack out-of-bounds NUL write in EF_SMARTZIP handler)
  * Drop "Rules-Requires-Root: no" (default).
  * Drop "Priority: optional" (default).
  * Update standards-version.
  * Disable redundant/duplicate Salsa CI jobs.
  * Drop no longer needed lintian override.

 -- Ural Tunaboyu <[email protected]>  Fri, 07 Nov 2025 15:39:29 +0100

** Changed in: unzip (Ubuntu)
       Status: New => Fix Released

** CVE added: None

** CVE added: None

** CVE added: None

** CVE added: https://cve.org/CVERecord?id=CVE-2021-4217

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163534

Title:
  Merge unzip 6.0-31 from Debian for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/2163534/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to