From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: bug#30415: Unzip CVE-2018-1000031 and others Date: Sat, 10 Feb 2018 13:57:28 -0500 Message-ID: <20180210185728.GA18894@jasmine.lan> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="tThc/1wpZn/ma/RB" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:57976) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ekaLd-0000Lm-NH for bug-guix@gnu.org; Sat, 10 Feb 2018 13:58:06 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ekaLa-0007Hb-In for bug-guix@gnu.org; Sat, 10 Feb 2018 13:58:05 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:57568) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ekaLa-0007HB-F2 for bug-guix@gnu.org; Sat, 10 Feb 2018 13:58:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ekaLa-0007Vq-2Y for bug-guix@gnu.org; Sat, 10 Feb 2018 13:58:02 -0500 Sender: "Debbugs-submit" Resent-Message-ID: Received: from eggs.gnu.org ([2001:4830:134:3::10]:57530) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ekaL7-00007n-PS for bug-guix@gnu.org; Sat, 10 Feb 2018 13:57:34 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ekaL4-0006fc-L8 for bug-guix@gnu.org; Sat, 10 Feb 2018 13:57:33 -0500 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:58633) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1ekaL4-0006fE-GB for bug-guix@gnu.org; Sat, 10 Feb 2018 13:57:30 -0500 Received: from localhost (c-76-124-202-137.hsd1.pa.comcast.net [76.124.202.137]) by mail.messagingengine.com (Postfix) with ESMTPA id 0755524406 for ; Sat, 10 Feb 2018 13:57:29 -0500 (EST) Content-Disposition: inline List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 30415@debbugs.gnu.org --tThc/1wpZn/ma/RB Content-Type: text/plain; charset=us-ascii Content-Disposition: inline We need to fix CVE-2018-1000031, CVE-2018-1000032, CVE-2018-1000033, CVE-2018-1000034, CVE-2018-1000035 in UnZip: http://seclists.org/oss-sec/2018/q1/134 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000031 and etc --tThc/1wpZn/ma/RB Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlp/QJgACgkQJkb6MLrK fwj2HhAA3h7kwVqLcW41YuuDUhRXutWinK1nmPfgA7OZZic9CZXAK49sRcSHpao4 1lISdvIUqHeIG3dkSwN+WrEHd4O7dwK3c0B2AXXV/9UD2Z/vQMppTiUG2lyd4flb mCf0mpaWfBz9ImmU6isVe7T87NNMw6Qppoak1RJ7c1EHri8jbu7DUyEs4g0ncoNr Ed566eso5drfSqukNUj5INBIwkUKO6Q6X5KnkGFjORoCQSBurPsX043hVPCv+YiX dZu83cTC/B+uuE/wxm7vwpiCx860mb6nY56UWQN/duAETnkyKf7YnTjnB50Ksk/2 yPeNviOn5KibqlmTfCeAjl8L4TOo2+SWO19yffC2fGmRWRAahqnyhFO4A3kTIo7k sR5/+BcKtfRpAN+XV85gdqKvLXYGi3sfhH+/8IiKwSVPKdhfApVA55zqrVrxZhTE nki7U6XDf9Ie9NV0Iszs5Rc7QUTbntniJNjQrSNrMUzbCQS7olo/TPz5/ACLurHE ZeWxcb66jUJxq3/ADqiXJ+gIAk0yjHkuLa46s/ycVPTb4UpBtSiE8IbRKFEbtLmh yn0zRm1MDxpsh9v4WshWgAUrE0DPZtigyB9aSd8zQnrINIi6DRdJDF99uk/mfkc1 3y3+v30NP9eQotPKM4uzH3rsAoG7jQu+y+xGfRirFvzywTKeoss= =OhBJ -----END PGP SIGNATURE----- --tThc/1wpZn/ma/RB--