Source: libio-compress-perl
Version: 2.219-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libio-compress-perl.

CVE-2026-48961[0]:
| IO::Compress versions from 2.207 before 2.220 for Perl ship a
| zipdetails CLI tool that crashes with undefined subroutine on Info-
| ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in
| bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875)
| with UID Size or GID Size set to 8, causing zipdetails to decode an
| 8-byte UID or GID value, it dispatches through decodeLitteEndian(),
| which calls a misnamed helper unpackValueQ. The actual function
| defined in the same file is unpackValue_Q (with underscore); the
| call raises 'Undefined subroutine &main::unpackValueQ' and the
| script exits with status 255.  Library callers of IO::Compress and
| IO::Uncompress are not affected; the defect is in the bundled CLI
| tool.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48961
    https://www.cve.org/CVERecord?id=CVE-2026-48961
[1] https://lists.security.metacpan.org/cve-announce/msg/40434383/
[2] 
https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to