Slackware: 2005-121-01: infozip Security Update
Summary
Here are the details from the Slackware 10.1 ChangeLog: patches/packages/infozip-5.52-i486-1.tgz: Upgraded to unzip552.tar.gz and zip231.tar.gz. These fix some buffer overruns if deep directory paths are packed into a Zip archive which could be a security vulnerability (for example, in a case of automated archiving or backups that use Zip). However, it also appears that these now use certain assembly instructions that might not be available on older CPUs, so if you have an older machine you may wish to take this into account before deciding whether you should upgrade. (* Security fix *)
Where Find New Packages
Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/infozip-5.52-i486-1.tgz
Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/infozip-5.52-i486-1.tgz
Updated package for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/infozip-5.52-i486-1.tgz
Updated package for Slackware 10.0:
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/infozip-5.52-i486-1.tgz
Updated package for Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/infozip-5.52-i486-1.tgz
Updated package for Slackware -current:
MD5 Signatures
Slackware 8.1 package:
d3fd87796f1303bf17b94611b4827d60 infozip-5.52-i486-1.tgz
Slackware 9.0 package:
af5f763f9dadadd473032bdebd76f085 infozip-5.52-i486-1.tgz
Slackware 9.1 package:
8d8e78360cd13b2a0f7f0db9a538d031 infozip-5.52-i486-1.tgz
Slackware 10.0 package:
c8ab2971135894313f241a91f11ff02b infozip-5.52-i486-1.tgz
Slackware 10.1 package:
0a94f56bc134975d5fff2f259121b9ad infozip-5.52-i486-1.tgz
Slackware -current package:
e90e33f4fbd2c312faa556bea61e123e infozip-5.52-i486-1.tgz
Installation Instructions
Installation instructions: Upgrade the package as root: # upgradepkg infozip-5.52-i486-1.tgz