Format: 1.8 Date: Fri, 29 Jun 2018 12:28:33 -0400 Source: zziplib Binary: zziplib-bin libzzip-0-13 libzzip-dev Architecture: powerpc Version: 0.13.62-2ubuntu0.2 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libzzip-0-13 - library providing read access on ZIP-archives - library libzzip-dev - library providing read access on ZIP-archives - development zziplib-bin - library providing read access on ZIP-archives - binaries Changes: zziplib (0.13.62-2ubuntu0.2) trusty-security; urgency=medium . * SECURITY UPDATE: invalid mem access in zzip_disk_fread - debian/patches/CVE-2018-6381.patch: check sizes in zzip/memdisk.c. - CVE-2018-6381 * SECURITY UPDATE: alignment and bus errors in __zzip_fetch_disk_trailer - debian/patches/CVE-2018-6484.patch: check sizes in zzip/zip.c. - CVE-2018-6484 - CVE-2018-6541 - CVE-2018-6869 * SECURITY UPDATE: bus error in zzip_disk_findfirst - debian/patches/CVE-2018-6540.patch: check endbuf in zzip/mmapped.c. - CVE-2018-6540 * SECURITY UPDATE: invalid memory dereference - debian/patches/CVE-2018-7725.patch: check zlib space in zzip/memdisk.c, zzip/mmapped.c. - CVE-2018-7725 * SECURITY UPDATE: bus error in __zzip_parse_root_directory - debian/patches/CVE-2018-7726-1.patch: check rootseek and rootsize in zzip/zip.c. - debian/patches/CVE-2018-7726-2.patch: check rootseek in zzip/zip.c. - debian/patches/CVE-2018-7726-3.patch: check zz_rootsize in zzip/zip.c. - CVE-2018-7726 Checksums-Sha1: 14418946eeb6766e6b8e51de56145556c78225c5 10350 zziplib-bin_0.13.62-2ubuntu0.2_powerpc.deb c69bc2dd5bf0ada1c594f03729189d6e10d30f8d 24440 libzzip-0-13_0.13.62-2ubuntu0.2_powerpc.deb 028e9752d221f5f4203c76c9ec0f99383f95381d 78810 libzzip-dev_0.13.62-2ubuntu0.2_powerpc.deb Checksums-Sha256: 21367e1049dbdac88e0cc9dea0de5b1b66b00f6ee29fe125501d75094d9d5cd5 10350 zziplib-bin_0.13.62-2ubuntu0.2_powerpc.deb 04e82960c88f64cac197cd75a739216b83cbbf41fd3e3c34a50fe6bdb8dffeff 24440 libzzip-0-13_0.13.62-2ubuntu0.2_powerpc.deb 5a7f13ffff96692805898f51dd43921feb860f080626a5c4bb2adcf8f8727b1a 78810 libzzip-dev_0.13.62-2ubuntu0.2_powerpc.deb Files: a9f055eee189ee0348c1ebd84990c65e 10350 utils optional zziplib-bin_0.13.62-2ubuntu0.2_powerpc.deb c6848a9ca16d4004f3e4b9c16563cb7d 24440 libs optional libzzip-0-13_0.13.62-2ubuntu0.2_powerpc.deb 2b5b0427a7f5c5224997b0e92ac5da9a 78810 libdevel optional libzzip-dev_0.13.62-2ubuntu0.2_powerpc.deb Original-Maintainer: Scott Howard