From: Mark Adler Subject: Fix bug in UZbunzip2() that incorrectly updated G.incnt Origin: https://github.com/madler/unzip/commit/5e2efcd633a4a1fb95a129a75508e7d769e767be Bug-Debian: https://bugs.debian.org/963996 X-Debian-version: 6.0-26 Fix bug in UZbunzip2() that incorrectly updated G.incnt. The update assumed a full buffer, which is not always full. This could result in a false overlapped element detection when a small bzip2-compressed file was unzipped. This commit remedies that. CVE: CVE-2019-13232 Upstream: https://sources.debian.org/src/unzip/6.0-29/debian/patches/25-cve-2019-13232-fix-bug-in-uzbunzip2.patch Signed-off-by: Thomas Perale --- a/extract.c +++ b/extract.c @@ -3052,7 +3052,7 @@ #endif G.inptr = (uch *)bstrm.next_in; - G.incnt = (G.inbuf + INBUFSIZ) - G.inptr; /* reset for other routines */ + G.incnt -= G.inptr - G.inbuf; /* reset for other routines */ uzbunzip_cleanup_exit: err = BZ2_bzDecompressEnd(&bstrm);