ELA-1826-1 zip security update

multiple vulnerabilities

2026-09-18
Packagezip
Version3.0-11+deb9u1 (stretch), 3.0-11+deb10u1 (buster), 3.0-12+deb11u1 (bullseye)
Related CVEs CVE-2018-13410


Multiple minor vulnerabilities was adressed together with the prime issue: Harry Sintonen discovered that the Info-ZIP zip program is prone to a command injection vulnerability if a specially crafted filename is processed.



For Debian 10 buster, these problems have been fixed in version 3.0-11+deb10u1.

For Debian 11 bullseye, these problems have been fixed in version 3.0-12+deb11u1.

For Debian 9 stretch, these problems have been fixed in version 3.0-11+deb9u1.

We recommend that you upgrade your zip packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.