Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "0.1.5.9+cvs.2007.04.28-5.1ubuntu0.14.04.1~esm1",
"binary_name": "libzipios++-dev"
},
{
"binary_version": "0.1.5.9+cvs.2007.04.28-5.1ubuntu0.14.04.1~esm1",
"binary_name": "libzipios++0c2a"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.7.2+dfsg-6ubuntu0.1",
"binary_name": "flightcrew"
},
{
"binary_version": "0.7.2+dfsg-6ubuntu0.1",
"binary_name": "libflightcrew-dev"
},
{
"binary_version": "0.7.2+dfsg-6ubuntu0.1",
"binary_name": "libflightcrew0v5"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.7.2+dfsg-10ubuntu0.1",
"binary_name": "flightcrew"
},
{
"binary_version": "0.7.2+dfsg-10ubuntu0.1",
"binary_name": "libflightcrew-dev"
},
{
"binary_version": "0.7.2+dfsg-10ubuntu0.1",
"binary_name": "libflightcrew0v5"
}
]
}