Debian Patches

Status for zziplib/0.13.62-3.3+deb11u1

Patch Description Author Forwarded Bugs Origin Last update
remove_extra_z_linking.patch package config file adds extra unneeded -lz=================================================================== Scott Howard <showard@debian.org> no debian
automake-compatibility.patch fix compatibility with newer versions of automake Since we want to run dh-autoreconf so that the package is always current
with respect to portability to new architectures, we also need to make sure
the Makefile.am works with the latest versions of automake. This requires
three fixes:
- fix configure.ac to not set RESOLVES to ' # ', which causes further
libraries on the line to be commented out
- fix duplicate references to a header in zzip/Makefile.am
- fix missing dependency on install-libLTLIBRARIES in the
install-exec-local target.

=== modified file 'zzip/Makefile.am'
===================================================================
Steve Langasek <steve.langasek@ubuntu.com> no
zziplib-CVE-2017-5974.patch =================================================================== no
zziplib-CVE-2017-5975.patch =================================================================== no
zziplib-CVE-2017-5976.patch =================================================================== no
zziplib-CVE-2017-5978.patch =================================================================== no
zziplib-CVE-2017-5979.patch =================================================================== no
zziplib-CVE-2017-5981.patch =================================================================== no
zziplib-unzipcat-NULL-name.patch =================================================================== no
merge-CVE-2018-6381.patch-from-jmoellers-12.patch merge CVE-2018-6381.patch from @jmoellers #12 Guido Draheim <guidod@gmx.de> yes debian upstream https://github.com/gdraheim/zziplib/commit/a803559fa9194be895422ba3684cf6309b6bb598 2018-02-01
One-more-free-to-avoid-memory-leak.patch One more free() to avoid memory leak. jmoellers <josef.moellers@suse.com> yes debian upstream https://github.com/gdraheim/zziplib/commit/0e1dadb05c1473b9df2d7b8f298dab801778ef99 2018-09-07
python2.diff =================================================================== no
Reject-the-ZIP-file-and-report-it-as-corrupt-if-the-.patch Reject the ZIP file and report it as corrupt if the size of the central directory and/or the offset of start of central directory point
beyond the end of the ZIP file. [CVE-2018-6484]
=?UTF-8?q?Josef=20M=C3=B6llers?= <josef@firefly.moellers.local> yes debian upstream https://github.com/gdraheim/zziplib/commit/0c0c9256b0903f664bca25dd8d924211f81e01d3 2018-02-02
need-to-check-on-endbuf-for-stored-files-15.patch need to check on endbuf for stored files #15 Guido Draheim <guidod@gmx.de> yes debian upstream https://github.com/gdraheim/zziplib/commit/72ec933663f738d8e166979aa7fd5590b2104a07 2018-02-05
check-zlib-space-to-be-within-buffer-39.patch check zlib space to be within buffer #39 Guido Draheim <guidod@gmx.de> yes debian upstream https://github.com/gdraheim/zziplib/commit/1ba660b3300d67b8ce9f6b96bbae0b36fa2d6b06 2018-03-13
check-rootseek-and-rootsize-to-be-positive-27.patch check rootseek and rootsize to be positive #27 Guido Draheim <guidod@gmx.de> yes debian upstream https://github.com/gdraheim/zziplib/commit/8f48323c181e20b7e527b8be7229d6eb1148ec5f 2018-03-13
check-rootseek-after-correction-41.patch check rootseek after correction #41 Guido Draheim <guidod@gmx.de> yes debian upstream https://github.com/gdraheim/zziplib/commit/19c9e4dc6c5cf92a38d0d23dbccac6993f9c41be 2018-03-13
fix-for-zz_rootsize-41.patch fix for zz_rootsize #41 Guido Draheim <guidod@gmx.de> yes debian upstream https://github.com/gdraheim/zziplib/commit/feae4da1a5c92100c44ebfcbaaa895959cc0829b 2018-03-15
Avoid-memory-leak-from-__zzip_parse_root_directory-1.patch Avoid memory leak from __zzip_parse_root_directory(). jmoellers <josef.moellers@suse.com> yes debian upstream https://github.com/gdraheim/zziplib/commit/9411bde3e4a70a81ff3ffd256b71927b2d90dcbb 2018-09-07
Avoid-memory-leak-from-__zzip_parse_root_directory-2.patch Avoid memory leak from __zzip_parse_root_directory(). jmoellers <josef.moellers@suse.com> yes debian upstream https://github.com/gdraheim/zziplib/commit/d2e5d5c53212e54a97ad64b793a4389193fec687 2018-09-07
CVE-2020-18442-2.patch commit 7e786544084548da7fcfcd9090d3c4e7f5777f7e

#68 return value of zzip_mem_disk_fread is signed

===================================================================
Guido Draheim <guidod@gmx.de> no 2021-01-04
CVE-2020-18442-4.patch commit 0a9db9ded9d15fbdb63bf5cf451920d0a368c00e

#68 return value of zzip_mem_disk_fread is signed

===================================================================
Guido Draheim <guidod@gmx.de> no 2021-01-04

All known versions for source package 'zziplib'

Links