REDHAT-BUG-1174851: Low severity Info-ZIP UnZip vulnerability
oCERT reports an unzip flaw discovered by Michele Spagnuolo, Google Security Team:
""" The write error shows a problem in extract.c:testcompreb(), which was not expecting an uncompressed size of zero for an EFNTSD extra block.
Proposed changes:
http://antinode.info/ftp/info-zip/unzip60/extract.c
extract.c:testcompreb() gets a new validity test. """
Acknowledgement:
Red Hat would like to thank oCERT for reporting these issues. oCERT acknowledges Michele Spagnuolo of the Google Security Team as the original reporter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1174851?
The severity of REDHAT-BUG-1174851 is classified as moderate.
How do I fix REDHAT-BUG-1174851?
To fix REDHAT-BUG-1174851, you should update to the latest version of Info-ZIP Unzip that includes the necessary patches.
What software is affected by REDHAT-BUG-1174851?
REDHAT-BUG-1174851 affects the Info-ZIP Unzip software.
Who discovered REDHAT-BUG-1174851?
REDHAT-BUG-1174851 was discovered by Michele Spagnuolo from the Google Security Team.
Is there a workaround for REDHAT-BUG-1174851?
Currently, there is no specific workaround for REDHAT-BUG-1174851 other than applying the patch.