Debian 10225 Published by

An unzip security update has been released for Debian 6 LTS



Package : unzip
Version : 6.0-4+deb6u3
CVE ID : CVE-2015-7696 CVE-2015-7697
Debian Bug : 802160 802162

Gustavo Grieco discovered with a fuzzer that unzip was vulnerable to a
heap overflow and to a denial of service with specially crafted
password-protected ZIP archives.

For the Debian 6 squeeze, these issues haven been fixed in unzip
6.0-4+deb6u3.
  Unzip security update for Debian 6 LTS