[ALSA-2021:4316] Low: zziplib security update
Type:
security
Severity:
low
Release date:
2021-11-12
Description:
The zziplib is a lightweight library to easily extract data from zip files. Security Fix(es): * zziplib: infinite loop via the return value of zzip_file_read() as used in unzzip_cat_file() (CVE-2020-18442) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 zziplib-0.13.68-9.el8.aarch64.rpm 2764da3923d477c4a857eb3aea37de969f1af911dbf8ee9585fc4b982fd8d6bd
aarch64 zziplib-utils-0.13.68-9.el8.aarch64.rpm 541edbccbb8fd3f457589cd00e423baa66d4141e0c30b8d0967be8b059d7efd7
aarch64 zziplib-devel-0.13.68-9.el8.aarch64.rpm f3aa81afa8078bcdb597f138a03e32bcb0c5e066faddb586f1248a6740bb4ba8
i686 zziplib-0.13.68-9.el8.i686.rpm 2fbf45a86d90093b4343f22de5437a08b7d22ce4cfe0e65d4ebb2cdead945ea1
i686 zziplib-devel-0.13.68-9.el8.i686.rpm 323dfc3babd7fc11857b451976d7a8db2cee8f4515ec381f8af8ec7604a998a6
ppc64le zziplib-0.13.68-9.el8.ppc64le.rpm 0adff6408684dbdb9f4efe9d5abfc079e4fe6fa93de02e764a28dfcde0eb18d1
ppc64le zziplib-utils-0.13.68-9.el8.ppc64le.rpm 8bd2c718545868a2046c4e34053d6238acf105683d0ba9c9de280e4c1e6f5426
ppc64le zziplib-devel-0.13.68-9.el8.ppc64le.rpm df8215705485856233cb2109446c9a874d0795933ab7d12e61b12153cc9aebb3
x86_64 zziplib-0.13.68-9.el8.x86_64.rpm b2b2d19c091b7f0620349e75c463de810ad4b907eea62abdeb4c8d4f1609f473
x86_64 zziplib-devel-0.13.68-9.el8.x86_64.rpm b7f706796dcf957aa0976f30f24b8b6a1ffdb8288266733dfaf50388f7bdb553
x86_64 zziplib-utils-0.13.68-9.el8.x86_64.rpm dba0c54c6531ad37545a8d1d4d6506d3ee9cc4426b97b7c6ab3298cbfe95deae
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.