Advisories ยป MGASA-2021-0033

Updated unzip package fixes a security vulnerability

Publication date: 17 Jan 2021
Modification date: 17 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-13232

Description

Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container,
leading to denial of service (resource consumption), aka a "better zip bomb"
issue (CVE-2019-13232).
                

References

SRPMS

7/core