From martin.pitt@canonical.com Wed Feb 15 08:39:21 2006 From: Martin Pitt To: ubuntu-security-announce@lists.ubuntu.com Cc: full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com Date: Wed, 15 Feb 2006 14:40:58 +0100 Subject: [Full-disclosure] [USN-248-2] unzip regression fix =========================================================== Ubuntu Security Notice USN-248-2 February 15, 2006 unzip regression fix https://launchpad.net/bugs/31457 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04 (Hoary Hedgehog) Ubuntu 5.10 (Breezy Badger) The following packages are affected: unzip The problem can be corrected by upgrading the affected package to version 5.51-2ubuntu0.4 (for Ubuntu 4.10), 5.51-2ubuntu1.4 (for Ubuntu 5.04), or 5.52-3ubuntu2.2 (for Ubuntu 5.10). In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: USN-248-1 fixed a vulnerability in unzip. However, that update inadvertedly changed the field order in the contents listing output, which broke unzip frontends like file-roller. The updated packages fix this regression. Updated packages for Ubuntu 4.10: Source archives: http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu0.4.diff.gz Size/MD5: 6474 da3e2aa0f07b0f6942c8ca7c811be8dc http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu0.4.dsc Size/MD5: 534 5863a6faa2e16fc470344be6ac0685a6 http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51.orig.tar.gz Size/MD5: 1112594 8a25712aac642430d87d21491f7c6bd1 amd64 architecture (Athlon64, Opteron, EM64T Xeon) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu0.4_amd64.deb Size/MD5: 148136 e56ba0b19a029ca74d3b9c962e4c3067 i386 architecture (x86 compatible Intel/AMD) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu0.4_i386.deb Size/MD5: 135098 8d7826896481ae1b36c25a2bb82b2d77 powerpc architecture (Apple Macintosh G3/G4/G5) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu0.4_powerpc.deb Size/MD5: 151026 501a8ca46b0fad1bd4f6db2111d58917 Updated packages for Ubuntu 5.04: Source archives: http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu1.4.diff.gz Size/MD5: 7291 085233db5f584b7ac0bb85f130094982 http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu1.4.dsc Size/MD5: 534 be84e01929f5caaae5ce229d6481d6bd http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51.orig.tar.gz Size/MD5: 1112594 8a25712aac642430d87d21491f7c6bd1 amd64 architecture (Athlon64, Opteron, EM64T Xeon) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu1.4_amd64.deb Size/MD5: 148326 f889fb1bed3fdfe4547cb3b06e68b22d i386 architecture (x86 compatible Intel/AMD) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu1.4_i386.deb Size/MD5: 136030 1443cd81161e7928862f4371f1477aa2 powerpc architecture (Apple Macintosh G3/G4/G5) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.51-2ubuntu1.4_powerpc.deb Size/MD5: 152608 60a9c1e55ecde86784f1e227f6532f1f Updated packages for Ubuntu 5.10: Source archives: http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.52-3ubuntu2.2.diff.gz Size/MD5: 9709 3a3d485c017577a2b6a465240308a629 http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.52-3ubuntu2.2.dsc Size/MD5: 534 2bb7488730bc34d3ca413f4a2dae48cd http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.52.orig.tar.gz Size/MD5: 1140291 9d23919999d6eac9217d1f41472034a9 amd64 architecture (Athlon64, Opteron, EM64T Xeon) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.52-3ubuntu2.2_amd64.deb Size/MD5: 159824 b3cecbc81298489ee20b27b3a174ee72 i386 architecture (x86 compatible Intel/AMD) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.52-3ubuntu2.2_i386.deb Size/MD5: 146510 1ce02df278333118ca892bfb841d1887 powerpc architecture (Apple Macintosh G3/G4/G5) http://security.ubuntu.com/ubuntu/pool/main/u/unzip/unzip_5.52-3ubuntu2.2_powerpc.deb Size/MD5: 164084 d7b948b8c503a3cf4eb720255cc0f416 [ Part 1.2, "Digital signature" Application/PGP-SIGNATURE ] [ 196bytes. ] [ Unable to print this part. ] [ Part 2: "Attached Text" ] _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/