From ${URL} : Two vulnerabilites were found in unzip 6.0, namely heap overflow and denial of service. Public post together with error report and reproducers are avalaible at: http://seclists.org/oss-sec/2015/q3/512 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
fixed w/Debian patchset. should be fine for stable. https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f65df71cdc392f85fd95ad5b8ef1508434e2a239
This issue was resolved and addressed in GLSA 201611-01 at https://security.gentoo.org/glsa/201611-01 by GLSA coordinator Aaron Bauman (b-man).
@maintainer(s), reopening for cleanup.
Can we please clean the vulnerable versions?
Cleanup PR: https://github.com/gentoo/gentoo/pull/3466
Tree is clean: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9801aee5391ae3e2c366107e3f0d21e8d29d95d3