An updated zip package has been released for CentOS-2
The following errata for CentOS-2 have been built and uploaded the the centos mirror:
RHSA-2004:634-01 Updated zip package fixes security issue
Files available:
zip-2.3-10.1.i386.rpm
More details are available from the RedHat web site at
https://rhn.redhat.com/errata/rh21as-errata.html
The easy way to make sure you are up to date with all the latest patches is to run:
# yum update