-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6439-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso August 14, 2026 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : zip CVE ID : not yet available Debian Bug : 1143866 Harry Sintonen discovered that the Info-ZIP zip program is prone to a command injection vulnerability if a specially crafted filename is processed. For the stable distribution (trixie), this problem has been fixed in version 3.0-15+deb13u1. We recommend that you upgrade your zip packages. For the detailed security status of zip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/zip Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmp+zQdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QVcBAAnd7x3SZhj3brsV9Hl4CBzKzkbuXBgRqVBs3wzPVZBLRS4gLfv0MQtfq+ J4t+MM61MllX2F1dZuQ4QPnSIMQfie9adjFZKWyv1srHdr+oBTN/TFxaCG9kZrTe 6xfWZAqja1U9EktisZPFG8lRZPxPRR6IL9SnohavGUzYhPPYAye4rBK9wHYpPjgV vNgsQq+Rc7fJLnWLbzNswSI76NIGHQjddF2qBQ7ZrsQ2HMXMtgdpxLk92VoOY72m jLCqANxgGJ9U7KDpJJfHO0Mx8XxD044i1O7ocdqRXevIxpcqcDUJRo6b5EXN5Myq vS4CHVbC89AXhhXVvxU/VDNgSHBWWz28AdeS23Y2kvsu0u70Oy/nkaNugCgYgEu7 pylFqtynccS9usDdjJ1eC1gu1OJx2mlD5ilRLfGFi/ZxUCV6MgMfub962VOKFXOI hdiJIAepjZak09xwJhP7LHYfPx0Tublnm3jTdwu9xeXcFHo9C522HV0WePSDuazu 3bmUQWEBITq8EOiMAX3r0qDMR61Z+D7BSu18QlGiI//bTylKFiIdyRVaOJgIbyLa Z3TqdiFDztDtFkE2xb+PRopRK+x7PPDs7LwHkkSRB5PjUvHh8zcPqzSCTky+pu8K iK5TDF0Ex/l5IlzLVuJY2NHxzpaUfPWQj94j+/IhVcmYTyEVsso= =1vBn -----END PGP SIGNATURE-----

