Debian Patches

Status for minizip/1.1-8+deb12u1

Patch Description Author Forwarded Bugs Origin Last update
include.patch add include that defines mkdir Michael Gilbert <mgilbert@debian.org> no
automake.patch apply automake build system from the zlib package no
traversal.patch fix directory traversal issues in miniunzip Michael Gilbert <mgilbert@debian.org> no debian
CVE-2023-45853.patch commit 73331a6a0481067628f065ffe87bb1d8f787d10c

Reject overflows of zip header fields in minizip.

This checks the lengths of the file name, extra field, and comment
that would be put in the zip headers, and rejects them if they are
too long. They are each limited to 65535 bytes in length by the zip
format. This also avoids possible buffer overflows if the provided
fields are too long.

===================================================================
Hans Wennborg <hans@chromium.org> no 2023-08-18

All known versions for source package 'minizip'

Links