I'm with the upstream Info-ZIP team. We've has a command injection issue reported against zip that we've been able to reproduce with the latest Debian sources. Attached patch is the proposed fix. Ping me if you need more details on reproduction steps
Credit where it is due — the Issue was discovered & reported by Harry Sintonen <sintonen@iki.fi>
We believe that the bug you reported is fixed in the latest version of
zip, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143866@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Santiago Vila <sanvila@debian.org> (supplier of updated zip package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 07 Aug 2026 16:15:00 +0200
Source: zip
Architecture: source
Version: 3.0-16
Distribution: unstable
Urgency: medium
Maintainer: Santiago Vila <sanvila@debian.org>
Changed-By: Santiago Vila <sanvila@debian.org>
Closes: 1143866
Changes:
zip (3.0-16) unstable; urgency=medium
.
* Stop prefixing patch filenames with numbers.
* Fix command injection issue. Closes: #1143866.
Reported upstream by Harry Sintonen <sintonen@iki.fi>.
* Drop "Rules-Requires-Root: no" (default).
* Drop "Priority: optional" (default).
* Update standards-version.
* Disable redundant/duplicate Salsa CI jobs.
* Drop no longer needed lintian override.
Checksums-Sha1:
94ecc652935e41d8fbd7cdf6db3d33c926f15ee7 1439 zip_3.0-16.dsc
378f3f1606521bf9cdc23f2d86a3236de82009eb 12512 zip_3.0-16.debian.tar.xz
b9f9cc45436915031d9ea228c94f88507d64e32d 5462 zip_3.0-16_source.buildinfo
Checksums-Sha256:
3f7a651a5e38105d56c7c190c4c388308cbab0a5a2ae97a7804a2e9ae37aefe6 1439 zip_3.0-16.dsc
fa79a0226f00f487b290489f62e1cd7f4a338df529a1e413fea4d168b8eee8f7 12512 zip_3.0-16.debian.tar.xz
8fa44cfd57a8391e86d423c087eb09d715971255b1e344f5167ce75140e927ca 5462 zip_3.0-16_source.buildinfo
Files:
e85217c6658b2c3958c56da5109285bf 1439 utils optional zip_3.0-16.dsc
993361600c239ef537118603b66f819d 12512 utils optional zip_3.0-16.debian.tar.xz
af3f161247b3adf49a6df063b5ed7507 5462 utils optional zip_3.0-16_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAmp16W8ACgkQQc5/C58b
izKlxwf/d0+Q14J0O3+9swYKJsCFcw26Mc8ZceSBj6HYxxPuU7oPGK1UJlgf8VcL
DT58+I8ARqw0yxT9R0eG+aygkWPtcJk/xgIgylLQlFgDeWiDr2bd/p20WQBn80wy
jD+FSIyBoy7LqNTNUQybJdWUTQqCykQ8/KLX5OR/S+aIKxudHlDLQ+DwoJxx7SIL
xjgNhRXIsXwhgE6jwzcyPPpKf0gMGpmkYQaqqNi4vflgsF/+e4zGQ6EEqb2TXMSJ
582Z57vaTestP4eUh73z8DBjI6A1RlQvWwtUM3pnSA+fBDguIftzZtf+5t+0HMiL
ZI29ykXrm+5dqPWHqUCFqbGTMt85VQ==
=KBDg
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of zip, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1143866@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Santiago Vila <sanvila@debian.org> (supplier of updated zip package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Tue, 11 Aug 2026 00:20:00 +0200 Source: zip Architecture: source Version: 3.0-15+deb13u1 Distribution: trixie-security Urgency: high Maintainer: Santiago Vila <sanvila@debian.org> Changed-By: Santiago Vila <sanvila@debian.org> Closes: 1143866 Changes: zip (3.0-15+deb13u1) trixie-security; urgency=high . * Fix command injection issue. Closes: #1143866. Checksums-Sha1: 11fe90cf5c87b0629846d144abfbf92045422bf7 1471 zip_3.0-15+deb13u1.dsc c9f4099ecf2772b53c2dd4a8e508064ce015d182 1118845 zip_3.0.orig.tar.gz 299aede2ff9becfbf4ea53d5a3dc31e3ae8be5ee 12464 zip_3.0-15+deb13u1.debian.tar.xz 6e6da7f5d89119e511123066e051b6a71a60c212 5100 zip_3.0-15+deb13u1_source.buildinfo Checksums-Sha256: 29ec4bc09dc1c7ee5865a3dbf483a54638cecfc3dccd81eefe2b8c80b9063966 1471 zip_3.0-15+deb13u1.dsc f0e8bb1f9b7eb0b01285495a2699df3a4b766784c1765a8f1aeedf63c0806369 1118845 zip_3.0.orig.tar.gz c0e284982dcfd6078aa02086dfc786e4f2a5df02ed3a94c6db73cf6c46849136 12464 zip_3.0-15+deb13u1.debian.tar.xz 3890a59aa4c50f4b492948bd43551de08c9d0858b7ed986c367885e217e88ef7 5100 zip_3.0-15+deb13u1_source.buildinfo Files: beaf5e7bf6d69bf58ae859db2c04cdcc 1471 utils optional zip_3.0-15+deb13u1.dsc 7b74551e63f8ee6aab6fbc86676c0d37 1118845 utils optional zip_3.0.orig.tar.gz bb87c8f7107d5628a9ebc1e34d2faec1 12464 utils optional zip_3.0-15+deb13u1.debian.tar.xz 51a332defece0518fdb5d0cdc7e18e4b 5100 utils optional zip_3.0-15+deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAmp68KIACgkQQc5/C58b izILPAgAj6zV7OQHkBhMdNFG1/+ABydTlYq0D1eGmnYTemUMl9HgVUbJ7zAaNs8P dNsBSzgRti9Mdvqi4ueZeesFwp2+5HtmBP85DFjUDNLAyo+teMyIITI/vhuC1Klo C63waccxD50wLRuEZXmbN2v2fTLKjfjHOBjtDfdSqB+RdUXMXBvNXDUZG4e8UzFu NhWt3HRNfMOloLv2U2ZPmUdtF55Sa9LIYpbEHymLSr4t5iKVASyaIrT7XRsWDsQp EtEe7TTnRg7s55C/t+4gs+Wt2Oxr80FAVvGZXt4VbGfGMNGM7iImPBJSoMRmlVmk 2n17Ic5uw5cFI6AjJEAPszYanbSIsw== =TSUY -----END PGP SIGNATURE-----