Revision Date: | 2004-12-16 | Version: | 502 |
Title: | RHSA-2004:634: zip security update (Low) |
Description: | The zip program is an archiving utility which can create ZIP-compatible archives.
A buffer overflow bug has been discovered in zip when handling long file names. An attacker could create a specially crafted path which could cause zip to crash or execute arbitrary instructions. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1010 to this issue.
Users of zip should upgrade to this updated package, which contains backported patches and is not vulnerable to this issue.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2004-1010 RHSA-2004:634-01
|
Platform(s): | Red Hat Enterprise Linux 3
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux 3 is installed AND zip is earlier than 0:2.3-16.1
AND zip is signed with Red Hat master key
|