Referenced CVEs:
CVE-2008-0888
Description:
===========================================================
Ubuntu Security Notice USN-589-1 March 20, 2008
unzip vulnerability
CVE-2008-0888
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
unzip 5.52-6ubuntu4.1
Ubuntu 6.10:
unzip 5.52-8ubuntu1.1
Ubuntu 7.04:
unzip 5.52-9ubuntu3.1
Ubuntu 7.10:
unzip 5.52-10ubuntu1.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Tavis Ormandy discovered that unzip did not correctly clean up pointers.
If a user or automated service was tricked into processing a specially
crafted ZIP archive, a remote attacker could execute arbitrary code with
user privileges.



