Fixed vulnerabilities:
- CVE-2014-9636 (VulnLIB link) Michal Zalewski discovered that unzip incorrectly handled certain malformed zip archives. If a user or automated system were tricked into processing a specially crafted zip archive, an attacker could possibly execute arbitrary code.
Affected releases:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Software description:
- unzip - De-archiver for .zip files
Solution:
- Check VulnLIB for fixes for CVEs listed above.
Source:
Thursday, 05.02.2015