From 1b1c382b9685519b6e9ee6e0937f5b4b7be2addc Mon Sep 17 00:00:00 2001 From: Christian Wiese Date: Mon, 29 Nov 2010 15:21:03 +0100 Subject: [PATCH] unzip: Updated (552 -> 60) (Securtiy!) The Unix port of UnZip 5.52 is reported to have a race-condition vulnerability, whereby a local attacker could change the permissions of the user's files during unpacking. (This has been assigned CVE ID CAN-2005-2475.) --- archiver/unzip/unzip.desc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/archiver/unzip/unzip.desc b/archiver/unzip/unzip.desc index f1a76f060..078587402 100644 --- a/archiver/unzip/unzip.desc +++ b/archiver/unzip/unzip.desc @@ -3,7 +3,7 @@ [COPY] This copyright note is auto-generated by ./scripts/Create-CopyPatch. [COPY] [COPY] Filename: package/.../unzip/unzip.desc -[COPY] Copyright (C) 2006 - 2009 The OpenSDE Project +[COPY] Copyright (C) 2006 - 2010 The OpenSDE Project [COPY] Copyright (C) 2004 - 2006 The T2 SDE Project [COPY] Copyright (C) 1998 - 2003 Clifford Wolf [COPY] @@ -31,8 +31,8 @@ [L] OpenSource [S] Stable -[V] 552 +[V] 60 [P] X 01---5---9 110.600 -[D] 2095070561 unzip552.tar.gz http://dl.sourceforge.net/sourceforge/infozip/ +[D] 2220360182 unzip60.tar.gz http://dl.sourceforge.net/sourceforge/infozip/