[CLSA-2026:1789375817] Fix CVE(s): CVE-2018-13410
Type:
security
Severity:
Critical
Release date:
2026-09-14 08:50:27 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in the unzip test command builder - debian/patches/CVE-2018-13410.patch: allocate one more byte for the command string built in check_zipfile() in zip.c, so that the quotes, separator and terminating NUL added around the archive name when -TT is used cannot write past the end of the buffer - CVE-2018-13410
CVEs fixed:
Updated packages:
  • zip_3.0-12+tuxcare.els1_amd64.deb
    sha:ccd79075dfc88b6394703476460a8df3fea37e5a
  • zip_3.0-12+tuxcare.els1_arm64.deb
    sha:432da1d7d4c7f5d06d5548894fbd78266d6b5a8e
  • zip_3.0-12+tuxcare.els1_armel.deb
    sha:da1e97d055539669e8868d9e5fdcfeaebbdc245c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.