Seems that Mark Adler has already addressed the zip bomb thing: https://github.com/madler/unzip Can we please get an official release of Zip/Unzip soon? Right now I'm being told to dump usage of InfoZip because of these vulnerabilities and I'd really rather not as there isn't much in the way of a replacement.
Seems that Mark Adler has already address the zip bomb thing: https://github.com/madler/unzip Can we please get an official release of Zip/Unzip soon? Right now I'm being told to dump usage of InfoZip because of these vulnerabilities and I'd really rather not as there isn't much in the way of a replacement.