Logo
componentzip
Name
zip
Version
3.0
Type
library
Description
-
Licenses
Info-ZIP
PURL
-
CPE
cpe:2.3:a:info-zip_project:zip:3.0:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
3.0

Patches#


#
Title
Author
Resolve
1
configure: Remove "Check C compiler type (optimization
Romain Naour <romain.naour@openwide.fr>
2
configure: Don't use host CPP
Romain Naour <romain.naour@openwide.fr>
3
Makefile: Use CFLAGS from command line
Romain Naour <romain.naour@openwide.fr>
4
configure: use LDFLAGS from command line
Romain Naour <romain.naour@openwide.fr>
5
unix/configure: remove GID/UID size check
Romain Naour <romain.naour@openwide.fr>
6
unix/configure: borrow the LFS test from autotools.
Romain Naour <romain.naour@openwide.fr>
7
timezone.c: needs time.h (fixes musl compile)
Peter Seiderer <ps.report@gmx.net>
8
Patch #8
Fabrice Fontaine <fontaine.fabrice@gmail.com>
9
Fix buffer overflow when filename contains unicode characters
Shengjing Zhu <shengjing.zhu@canonical.com>
10
Fix buffer overflow when using '-T -TT'
Florent 'Skia' Jacquet <florent.jacquet@canonical.com>
CVE-2018-13410

Vulnerabilities#


Name
Analysis
Description
Patched
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands