Format: 1.8 Date: Fri, 29 Jun 2018 12:28:33 -0400 Source: zziplib Binary: zziplib-bin libzzip-0-13 libzzip-dev Architecture: ppc64el Version: 0.13.62-2ubuntu0.2 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libzzip-0-13 - library providing read access on ZIP-archives - library libzzip-dev - library providing read access on ZIP-archives - development zziplib-bin - library providing read access on ZIP-archives - binaries Changes: zziplib (0.13.62-2ubuntu0.2) trusty-security; urgency=medium . * SECURITY UPDATE: invalid mem access in zzip_disk_fread - debian/patches/CVE-2018-6381.patch: check sizes in zzip/memdisk.c. - CVE-2018-6381 * SECURITY UPDATE: alignment and bus errors in __zzip_fetch_disk_trailer - debian/patches/CVE-2018-6484.patch: check sizes in zzip/zip.c. - CVE-2018-6484 - CVE-2018-6541 - CVE-2018-6869 * SECURITY UPDATE: bus error in zzip_disk_findfirst - debian/patches/CVE-2018-6540.patch: check endbuf in zzip/mmapped.c. - CVE-2018-6540 * SECURITY UPDATE: invalid memory dereference - debian/patches/CVE-2018-7725.patch: check zlib space in zzip/memdisk.c, zzip/mmapped.c. - CVE-2018-7725 * SECURITY UPDATE: bus error in __zzip_parse_root_directory - debian/patches/CVE-2018-7726-1.patch: check rootseek and rootsize in zzip/zip.c. - debian/patches/CVE-2018-7726-2.patch: check rootseek in zzip/zip.c. - debian/patches/CVE-2018-7726-3.patch: check zz_rootsize in zzip/zip.c. - CVE-2018-7726 Checksums-Sha1: 125218206e7f1d747bdd3c2e8efcf72bf00d439f 11204 zziplib-bin_0.13.62-2ubuntu0.2_ppc64el.deb b3512f90de914e0cc0e622fc21a21952e740b6a4 25054 libzzip-0-13_0.13.62-2ubuntu0.2_ppc64el.deb 42f75199a4077804948a72dc79b6333a107a4403 83258 libzzip-dev_0.13.62-2ubuntu0.2_ppc64el.deb Checksums-Sha256: ca1343e368e6edaaa3afd3bac1443b99cc5b2f48b8a1b62270351138153f24cf 11204 zziplib-bin_0.13.62-2ubuntu0.2_ppc64el.deb eceb94cc898d2dcfa5af99032e5ae4e1d68a25d5cdd1bce3539a019249fba199 25054 libzzip-0-13_0.13.62-2ubuntu0.2_ppc64el.deb f0fc80a1090e69537b63b3335ecfe82ee76cc8172677e1954aa24e6033fa64d8 83258 libzzip-dev_0.13.62-2ubuntu0.2_ppc64el.deb Files: 901556429931d3e9f8a6b3bc0eb23c5b 11204 utils optional zziplib-bin_0.13.62-2ubuntu0.2_ppc64el.deb 7873758cbc1d36aeb5a53b3e1c2270f7 25054 libs optional libzzip-0-13_0.13.62-2ubuntu0.2_ppc64el.deb 6754c2e16d01a6230a7bac74b3c0c7dd 83258 libdevel optional libzzip-dev_0.13.62-2ubuntu0.2_ppc64el.deb Original-Maintainer: Scott Howard