CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6439-1 zip - security update

unknown
Harry Sintonen discovered that the Info-ZIP zip program is prone to a command injection vulnerability if a specially crafted filename is processed. https://security-tracker.debian.org/tracker/DSA-6439-1

CSIRTS triage

What
A command injection vulnerability in the zip program allows code execution via specially crafted filenames.
Who is affected
All users archiving files with untrusted or crafted filenames using affected zip versions.
Urgency
High; command injection poses significant risk and warrants prompt patching.
Action
Update to the patched version of zip provided by Debian or the upstream Info-ZIP project.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch zip

Get an email when a new zip advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00350.html

More from Debian Security Advisories