-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 22 Oct 2015 12:12:46 +0200 Source: unzip Binary: unzip Architecture: source Version: 6.0-19 Distribution: unstable Urgency: medium Maintainer: Santiago Vila <sanvila@debian.org> Changed-By: Santiago Vila <sanvila@debian.org> Description: unzip - De-archiver for .zip files Closes: 802160 802162 Changes: unzip (6.0-19) unstable; urgency=medium . * Fix infinite loop when extracting password-protected archive. This is CVE-2015-7697. Closes: #802160. * Fix heap overflow when extracting password-protected archive. This is CVE-2015-7696. Closes: #802162. * Fix additional unsigned overflow on invalid input. * Thanks a lot to Raphaël Hertzog for the squeeze-lts release, from which this upload is mainly derived. Checksums-Sha1: f0195938e7aa520a307870dfb7b24d6d5338ee1b 1329 unzip_6.0-19.dsc e9365b87fff0d7c5c1888568b33bc88008f9b60c 16616 unzip_6.0-19.debian.tar.xz Checksums-Sha256: 44ff301e56edc2dedc4b180d781966363b48ae613ca4b677876c17dd40243647 1329 unzip_6.0-19.dsc 1dbe8726dbb4ce7ac645e4700421d3a30650bd257ffe2271ac4be8dc4c939208 16616 unzip_6.0-19.debian.tar.xz Files: 9aed6673bd2113f3ef6dc862a8541a8d 1329 utils optional unzip_6.0-19.dsc eace08b51823c3cec0db075171184728 16616 utils optional unzip_6.0-19.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCAAGBQJWKLbuAAoJEEHOfwufG4syynwH/jX+92YSPA3uUbKBv3MTEJI/ oXP4ffn+ibSIbhb0Uuwedi4ZadxCOG2JKvpdgw0sla6IGgPMRf3DMSIZ0feTz3lo qUoeWt12OJu7w12borIbRaMC3RlgPa0xfQUENut5v+AIEtQhkQKQPrq8cYm3vuw/ 2JECzZiND45oGe295jxaHBlrwRsfR80Kp19CRqjsLQNlXYS8Drpw68nDP92siI+g 8C5zA3ZN0n6ndzXrWOaFW/or2XTTvrX/0q8PJab8LYdPBn9Pqsp64qwKiwpx9cJp u91tgGmIOuy6WVAir/6GCtEtffADKJ+0JD3SeUZq88qQmbl4wi5lHboh2A4RD6Q= =5aUy -----END PGP SIGNATURE-----