| Package | zip |
|---|---|
| Version | 3.0-11+deb9u1 (stretch), 3.0-11+deb10u1 (buster), 3.0-12+deb11u1 (bullseye) |
| Related CVEs | CVE-2018-13410 |
Multiple minor vulnerabilities was adressed together with the prime issue: Harry Sintonen discovered that the Info-ZIP zip program is prone to a command injection vulnerability if a specially crafted filename is processed.
For Debian 10 buster, these problems have been fixed in version 3.0-11+deb10u1.
For Debian 11 bullseye, these problems have been fixed in version 3.0-12+deb11u1.
For Debian 9 stretch, these problems have been fixed in version 3.0-11+deb9u1.
We recommend that you upgrade your zip packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.