--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2018-6abfa0012f
2018-07-19 18:02:50.871473
--------------------------------------------------------------------------------Name        : perl-Archive-Zip
Product     : Fedora 28
Version     : 1.60
Release     : 3.fc28
URL         : https://metacpan.org/dist/Archive-Zip
Summary     : Perl library for accessing Zip archives
Description :
The Archive::Zip module allows a Perl program to create, manipulate,
read, and write Zip archive files.
Zip archives can be created, or you can read from existing zip files.
Once created, they can be written to files, streams, or strings.
Members can be added, removed, extracted, replaced, rearranged, and
enumerated.  They can also be renamed or have their dates, comments,
or other attributes queried or modified.  Their data can be compressed
or uncompressed as needed.  Members can be created from members in
existing Zip files, or from existing directories, files, or strings.

--------------------------------------------------------------------------------Update Information:

This release fixes a directory and symbolic link traversal vulnerability in
Archive::Zip::Archive Perl module that allows an attacker to writite into an
arbitrary file accesible by a local user.
--------------------------------------------------------------------------------ChangeLog:

* Tue Jul 10 2018 Petr Pisar  - 1.60-3
- Fix CVE-2018-10860 (a directory and symbolic link traversal) (bug #1596132)
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #1591449 - CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip
        https://bugzilla.redhat.com/show_bug.cgi?id=1591449
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-6abfa0012f' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YCANPBQBD746IUDZBWMYW7HM77JRL3WG/

Fedora 28: perl-Archive-Zip Security Update

July 19, 2018
This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by...

Summary

The Archive::Zip module allows a Perl program to create, manipulate,

read, and write Zip archive files.

Zip archives can be created, or you can read from existing zip files.

Once created, they can be written to files, streams, or strings.

Members can be added, removed, extracted, replaced, rearranged, and

enumerated. They can also be renamed or have their dates, comments,

or other attributes queried or modified. Their data can be compressed

or uncompressed as needed. Members can be created from members in

existing Zip files, or from existing directories, files, or strings.

This release fixes a directory and symbolic link traversal vulnerability in

Archive::Zip::Archive Perl module that allows an attacker to writite into an

arbitrary file accesible by a local user.

* Tue Jul 10 2018 Petr Pisar - 1.60-3

- Fix CVE-2018-10860 (a directory and symbolic link traversal) (bug #1596132)

[ 1 ] Bug #1591449 - CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip

https://bugzilla.redhat.com/show_bug.cgi?id=1591449

su -c 'dnf upgrade --advisory FEDORA-2018-6abfa0012f' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YCANPBQBD746IUDZBWMYW7HM77JRL3WG/

FEDORA-2018-6abfa0012f 2018-07-19 18:02:50.871473 Product : Fedora 28 Version : 1.60 Release : 3.fc28 URL : https://metacpan.org/dist/Archive-Zip Summary : Perl library for accessing Zip archives Description : The Archive::Zip module allows a Perl program to create, manipulate, read, and write Zip archive files. Zip archives can be created, or you can read from existing zip files. Once created, they can be written to files, streams, or strings. Members can be added, removed, extracted, replaced, rearranged, and enumerated. They can also be renamed or have their dates, comments, or other attributes queried or modified. Their data can be compressed or uncompressed as needed. Members can be created from members in existing Zip files, or from existing directories, files, or strings. This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user. * Tue Jul 10 2018 Petr Pisar - 1.60-3 - Fix CVE-2018-10860 (a directory and symbolic link traversal) (bug #1596132) [ 1 ] Bug #1591449 - CVE-2018-10860 perl-Archive-Zip: Directory traversal in Archive::Zip https://bugzilla.redhat.com/show_bug.cgi?id=1591449 su -c 'dnf upgrade --advisory FEDORA-2018-6abfa0012f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YCANPBQBD746IUDZBWMYW7HM77JRL3WG/

Change Log

References

Update Instructions

Severity
Product : Fedora 28
Version : 1.60
Release : 3.fc28
URL : https://metacpan.org/dist/Archive-Zip
Summary : Perl library for accessing Zip archives

Related News