-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 3.0 (quilt) Source: unzip Binary: unzip Architecture: any Version: 6.0-8+deb7u1 Maintainer: Santiago Vila <[email protected]> Homepage: http://www.info-zip.org/UnZip.html Standards-Version: 3.9.2 Build-Depends: libbz2-dev Package-List: unzip deb utils optional Checksums-Sha1: abf7de8a4018a983590ed6f5cbd990d4740f8a22 1376845 unzip_6.0.orig.tar.gz efa3c8368010fb14355ed6121f1d2018a1122fec 13694 unzip_6.0-8+deb7u1.debian.tar.gz Checksums-Sha256: 036d96991646d0449ed0aa952e4fbe21b476ce994abc276e49d30e686708bd37 1376845 unzip_6.0.orig.tar.gz 02aeb43c88ba38849597e03920422f9612ce8c658f558cd4b34c45b9837a6a5b 13694 unzip_6.0-8+deb7u1.debian.tar.gz Files: 62b490407489521db863b523a7f86375 1376845 unzip_6.0.orig.tar.gz 6d0673b9a6cc740dfb0b4fa20af5a824 13694 unzip_6.0-8+deb7u1.debian.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUnt0sAAoJEAVMuPMTQ89EiwMP/1Onu+Av+ClPlL814So4R+L1 GxF+6crkGqAVIftukSlMZ9MyhPSNEVrll2QaI2f3mcHBskDJSWf9nCNAv69vtl1l X9/dKNXQKq7Nb9i/vNW1RI4X0xKezj1pgfNM49NJkE0Z+OtclphqVkTPWx40c83+ Gr1kXv3JKNb/Au0aJg9H1nEYIzmw0eeqwTSWsd4A7I5WLjmRjx/6svdk5BPPAURu 1vKQ4IOXq2cYfVrf8a5/Gy5MnNZlQykDNohCZPJ+b1z5YjRIu7SdRN8hrM4XKGb5 SpTe7cv88f+agmVfiHvhUpYp3Z6XqmCZWEQHep8iGv/0ruis0oETlN58Q8owyr3W Nwc5Qifo/HhVXS7UwcTPiBneq15sHb4jTUYJ3G3zhT3T2g15TnlK7+f21dQLnKs2 ou4gYKn28AgMSwmoqRxB2tcFpruDv/3KZLxlzlNTxZLiqM/f2PmHVHuGCgsWz0w8 pVoiVgv95KVPsAb2VbpwBJx5v9gllqT1vpL4ZflTzqL6xe/EFtnT+dSjXWJ6G7jb F+oajY9cwrVePYec9sedEvQE8lilksWVkrW4nz1gbdmNVJTNy4fDpVrKCbznu0nq TkUnwaAY9WmR/KpZTCXNSmx7yMWiNVOsgTMtlQMhaZ50eIVJ+H+IBK/CbEqv6sgQ oz12qfD0dR4QUCDK/IAl =3dnI -----END PGP SIGNATURE----- Changes: unzip (6.0-8+deb7u1) wheezy-security; urgency=high * Non-maintainer upload by the Security Team. * Apply upstream fix for three security bugs. CVE-2014-8139: CRC32 verification heap-based overflow CVE-2014-8140: out-of-bounds write issue in test_compr_eb() CVE-2014-8141: out-of-bounds read issues in getZip64Data() (Closes: #773722) -- Salvatore Bonaccorso <[email protected]> Fri, 26 Dec 2014 20:04:35 +0100