Report forwarded
to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>: Bug#842993; Package zip.
(Wed, 02 Nov 2016 21:21:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Bergen A van <x1@ziggo.nl>:
New Bug report received and forwarded. Copy sent to Santiago Vila <sanvila@debian.org>.
(Wed, 02 Nov 2016 21:21:04 GMT) (full text, mbox, link).
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: /usr/bin/zip: Zip (or unzip) does not ALWAYS preserve the file time stamp
correctly
Date: Wed, 02 Nov 2016 22:00:14 +0100
Package: zip
Version: 3.0-8
Severity: normal
File: /usr/bin/zip
Dear Maintainer,
BUG: Zip (or unzip) does not ALWAYS preserve the file time stamp
correctly as shown in example 1 and 2.
EXAMPLE 1:
---------
$ cat >a1.txt
$ touch -t 201611021508.09 a1.txt
$ zip a1.zip a1.txt
$ mv a1.txt a2.txt
$ unzip a1.zip
time stamp of a1.txt : 201611021508.10
time stamp of a2.txt : 201611021508.09
EXAMPLE 2:
----------
$ cat >b1.txt
$ touch -t 201611021508.06 b1.txt
$ zip b1.zip b1.txt
$ mv b1.txt b2.txt
$ unzip b1.zip
time stamp of b1.txt : 201611021508.06
time stamp of b2.txt : 201611021508.06
-- System Information:
Debian Release: 8.6
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 3.16.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages zip depends on:
ii libbz2-1.0 1.0.6-7+b3
ii libc6 2.19-18+deb8u6
Versions of packages zip recommends:
ii unzip 6.0-16+deb8u2
zip suggests no packages.
-- no debconf information
Information forwarded
to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>: Bug#842993; Package zip.
(Thu, 03 Nov 2016 15:09:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Santiago Vila <sanvila@unex.es>:
Extra info received and forwarded to list. Copy sent to Santiago Vila <sanvila@debian.org>.
(Thu, 03 Nov 2016 15:09:03 GMT) (full text, mbox, link).
To: Bergen A van <x1@ziggo.nl>, 842993@bugs.debian.org
Subject: Re: Bug#842993: /usr/bin/zip: Zip (or unzip) does not ALWAYS preserve
the file time stamp correctly
Date: Thu, 3 Nov 2016 16:08:15 +0100 (CET)
On Wed, 2 Nov 2016, Bergen A van wrote:
> Package: zip
> Version: 3.0-8
> Severity: normal
> File: /usr/bin/zip
>
> Dear Maintainer,
>
> BUG: Zip (or unzip) does not ALWAYS preserve the file time stamp
> correctly as shown in example 1 and 2.
This is a limitation of the zip archive format itself.
Because the old MS-DOS filesystem had a resolution of 2 seconds.
the designers of the zip format decided that 5 bits were enough
to store the seconds in a timestamp.
So the stored value (a number between 0 and 31) is multiplied
by two to get the actual number of seconds in the timestamp,
and as a result all timestamps have an even number of seconds.
May I close this bug?
Information forwarded
to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>: Bug#842993; Package zip.
(Fri, 09 Dec 2016 00:09:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Santiago Vila <sanvila@unex.es>:
Extra info received and forwarded to list. Copy sent to Santiago Vila <sanvila@debian.org>.
(Fri, 09 Dec 2016 00:09:02 GMT) (full text, mbox, link).
Subject: Re: /usr/bin/zip: Zip (or unzip) does not ALWAYS preserve the file
time stamp correctly
Date: Fri, 9 Dec 2016 01:08:17 +0100 (CET)
reassign 842993 unzip
retitle 842993 unzip does not accurately restore timestamps
thanks
The author has a fix for this. It's really a bug in unzip.
Thanks.
Bug reassigned from package 'zip' to 'unzip'.
Request was from Santiago Vila <sanvila@unex.es>
to control@bugs.debian.org.
(Fri, 09 Dec 2016 00:09:04 GMT) (full text, mbox, link).
No longer marked as found in versions zip/3.0-8.
Request was from Santiago Vila <sanvila@unex.es>
to control@bugs.debian.org.
(Fri, 09 Dec 2016 00:09:05 GMT) (full text, mbox, link).
Changed Bug title to 'unzip does not accurately restore timestamps' from '/usr/bin/zip: Zip (or unzip) does not ALWAYS preserve the file time stamp correctly'.
Request was from Santiago Vila <sanvila@unex.es>
to control@bugs.debian.org.
(Fri, 09 Dec 2016 00:09:05 GMT) (full text, mbox, link).
Reply sent
to Santiago Vila <sanvila@debian.org>:
You have taken responsibility.
(Sun, 11 Dec 2016 21:09:14 GMT) (full text, mbox, link).
Notification sent
to Bergen A van <x1@ziggo.nl>:
Bug acknowledged by developer.
(Sun, 11 Dec 2016 21:09:14 GMT) (full text, mbox, link).
Source: unzip
Source-Version: 6.0-21
We believe that the bug you reported is fixed in the latest version of
unzip, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 842993@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Santiago Vila <sanvila@debian.org> (supplier of updated unzip package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sun, 11 Dec 2016 21:03:30 +0100
Source: unzip
Binary: unzip
Architecture: source
Version: 6.0-21
Distribution: unstable
Urgency: medium
Maintainer: Santiago Vila <sanvila@debian.org>
Changed-By: Santiago Vila <sanvila@debian.org>
Description:
unzip - De-archiver for .zip files
Closes: 836051842993847485847486
Changes:
unzip (6.0-21) unstable; urgency=medium
.
* Rename all debian/patches/* to have .patch ending.
* Update 12-cve-2014-9636-test-compr-eb.patch to follow revised
patch "unzip-6.0_overflow3.diff" from mancha (patch author).
Update also to follow upstream coding style.
* Drop workaround for gcc optimization bug on ARM (GCC Bug #764732)
in the hope that it's not present anymore in GCC-6.
* Allow source to be cross-built. Closes: #836051.
* Do not ignore Unix Timestamps. Closes: #842993. Patch by the author.
* Fix CVE-2014-9913, buffer overflow in unzip. Closes: #847485.
Patch by the author.
* Fix CVE-2016-9844, buffer overflow in zipinfo. Closes: #847486.
Patch by the author.
Checksums-Sha1:
9fb43c2840bacd6325798459cacd140405d9d936 1344 unzip_6.0-21.dsc
c7401c4282cbf39f4ad3a869400dcf8454a16f4b 17740 unzip_6.0-21.debian.tar.xz
Checksums-Sha256:
c51fca0f9d8af19ead119addf4b56ea25443b64951b85eceb873f0ca76b378d4 1344 unzip_6.0-21.dsc
8accd9d214630a366476437a3ec1842f2e057fdce16042a7b19ee569c33490a3 17740 unzip_6.0-21.debian.tar.xz
Files:
df5279e9986e9c7b536733768162e550 1344 utils optional unzip_6.0-21.dsc
25ffeb578788adf5b312a539733078f9 17740 utils optional unzip_6.0-21.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCAAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAlhNsVsACgkQQc5/C58b
izICoAgAqSDyRKhDMgzUa3XzCCexomp2bx2RuwfOFetuuY0issWsOyn/DtWwwAFp
WZb4lSRDZ992YuPi5nhvs+U5NYbGGrkGaNivUc/fgJELlYMIQ9w2sqksL1RFQ8Pz
PKCaOFArgTjDNM2pAMk8ZR/C0UkR1o+1VYsq5uWLgRmwnPOQgmGS1w5AjxRizsEy
VSfNZNZcZz+ksS34UPvkLFNgtU9rNhW4LlMs11FNm3zTQlvc75xws+Jqx8UHeiyV
yxBDJ3VnUG5MEPuR9SLafDKPJ1XkbqMknhGCWYDd6Zy6thzNOKUr1rCOWJyG/nT7
sy6aY5A7RuyoVIliTi8HnCmwHR58sQ==
=r2fY
-----END PGP SIGNATURE-----
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Fri, 27 Jan 2017 11:57:43 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the GNU General
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.