Description: Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.
Fedora and openSUSE have this patched: https://src.fedoraproject.org/rpms/unzip/blob/master/f/unzip-6.0-overflow-long- fsize.patch https://build.opensuse.org/package/view_file/openSUSE:Factory/unzip/unzip60-cfactorstr_overflow.patch
ping
(In reply to Sam James from comment #2) > ping ping
We are not affected. Gentoo's unzip package is based on Debian's unzip package (currently at patchlevel 25). Debian applies 07-increase-size-of-cfactorstr.patch which we also do and upstream confirmed that this will mitigate the problem, https://sourceforge.net/p/infozip/bugs/53/#ba07. Closing as INVALID because CVE doesn't apply to Gentoo.