[Esd-l] Re: ALERT: Another ZIP trick is out...

John D. Hardin jhardin at impsec.org
Wed Mar 17 21:02:10 PST 2004

On Wed, 17 Mar 2004, John D. Hardin wrote:

> You need to have a version of unzip that supports the -P
> (password) argument. 5.50 and later work, 5.40 and below do not.

unzip 5.50 has some security fixes, so I recommend using that.

See http://www.info-zip.org/pub/infozip/UnZip.html for binaries and
source code. See http://rpmfind.net/ for RPMs. Etc. You should know
where to get software updates for your platform... :)

