Please sync unzip 5.52-11 (main) from Debian unstable (main).

Bug #238620 reported by Kees Cook
4
Affects Status Importance Assigned to Milestone
unzip (Ubuntu)
Invalid
Wishlist
Unassigned

Bug Description

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects ubuntu/unzip
 status confirmed
 importance wishlist
 subscribe ubuntu-archive

Please sync unzip 5.52-11 (main) from Debian unstable (main).

Explanation of the Ubuntu delta and why it can be dropped:

Security fixes applied upstream.

Changelog since current intrepid version 5.52-10ubuntu2:

unzip (5.52-11) unstable; urgency=high

  * Apply patch from Tavis Ormandy to address invalid free() calls in
    the inflate_dynamic() function (CVE-2008-0888).

 -- Santiago Vila <email address hidden> Thu, 20 Mar 2008 17:53:00 +0100

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)
Comment: Kees Cook <email address hidden>

iEYEARECAAYFAkhNYboACgkQH/9LqRcGPm2cLQCdF8C6VcbmWkrdZPapC7jVBqlg
V64AnApTj8Dqi3c/YQnGZSR9+hlUL2wQ
=zQOC
-----END PGP SIGNATURE-----

Revision history for this message
Sebastien Bacher (seb128) wrote :

Getting binaries for intrepid...
[Updating] unzip (5.52-10ubuntu2 [Ubuntu] < 5.52-11 [Debian])
 * Trying to add unzip...
  - <unzip_5.52.orig.tar.gz: already in distro - downloading from librarian>
  - <unzip_5.52-11.dsc: downloading from http://ftp.debian.org/debian/>
  - <unzip_5.52-11.diff.gz: downloading from http://ftp.debian.org/debian/>
I: unzip [main] -> unzip_5.52-10ubuntu2 [main].

Changed in unzip:
status: Confirmed → Fix Released
Revision history for this message
Thierry Carrez (ttx) wrote :

This should not be synced, but merged.
There are two remaining deb/ubuntu deltas :
  * UTF-8 patch
  * configure with large file support

I'm working on the merge (bug 239686).
pitti killed the sync, closing the bug as Invalid.

Changed in unzip:
status: Fix Released → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.