I have not had time to check over the patch listed on Ubuntu's repository, but here is a link: https://launchpad.net/ubuntu/+source/unzip/6.0-12ubuntu1.3 Here's a link to more info: http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1315.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1315 https://security-tracker.debian.org/tracker/CVE-2015-1315
Auto-assigned to maintainer ehaupt@FreeBSD.org
I may have time this evening to work up a patch for our port, but I don't have time right this second.
Take.
A commit references this bug: Author: delphij Date: Tue Feb 17 22:03:34 UTC 2015 New revision: 379193 URL: https://svnweb.freebsd.org/changeset/ports/379193 Log: Document unzip heap based buffer overflow in iconv patch. PR: ports/197772 Changes: head/security/vuxml/vuln.xml
I've committed a fix as r379192-379193 and merged to quaterly branch as 379194.