Re: [SECURITY] [DLA 1846-1] unzip security update

2019-07-28 Thread Markus Koschany
Hi Salvatore, Am 28.07.19 um 04:37 schrieb Salvatore Bonaccorso: [...] > There is a functional regression by this update in unzip, with a patch > provided by Mark Adler, cf. #932404: > > To reproduce the issue: > > wget > http://ftp.mozilla.org/pub/firefox/releases/68.0.1/linux-x86_64/en-US/fir

Re: [SECURITY] [DLA 1846-1] unzip security update

2019-07-28 Thread Salvatore Bonaccorso
Hi Markus, On Sun, Jul 07, 2019 at 10:09:22PM +0200, Markus Koschany wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Package: unzip > Version: 6.0-16+deb8u4 > CVE ID : CVE-2019-13232 > Debian Bug : 931433 > > David Fifield discovered a way to construct