Filling of CVE-2019-13232 introduced a check against a zipbomb and many (Debian, NixOS) distributions patched against it.
It seems that one of the test of zip-archive is using an archive that triggers this check and the test fails. Please see a test failed in NixOS https://logs.nix.ci/?key=nixos/nixpkgs.64909&attempt_id=cc70c8f9-1d57-4b64-8073-42691767eeda
More information about the attach https://www.bamsoftware.com/hacks/zipbomb/
And the patch applied can be found at madler/unzip@47b3cea
Filling of
CVE-2019-13232introduced a check against a zipbomb and many (Debian, NixOS) distributions patched against it.It seems that one of the test of zip-archive is using an archive that triggers this check and the test fails. Please see a test failed in NixOS https://logs.nix.ci/?key=nixos/nixpkgs.64909&attempt_id=cc70c8f9-1d57-4b64-8073-42691767eeda
More information about the attach https://www.bamsoftware.com/hacks/zipbomb/
And the patch applied can be found at madler/unzip@47b3cea