Oval Definition:oval:com.redhat.rhsa:def:20060663
Revision Date:2008-03-20Version:646
Title:RHSA-2006:0663: ncompress security update (Low)
Description:The ncompress package contains file compression and decompression utilities, which are compatible with the original UNIX compress utility (.Z file extensions).

  • Tavis Ormandy of the Google Security Team discovered a lack of bounds checking in ncompress. An attacker could create a carefully crafted file that could execute arbitrary code if uncompressed by a victim. (CVE-2006-1168)

    In addition, two bugs that affected Red Hat Enterprise Linux 4 ncompress packages were fixed:

    The display statistics and compression results in verbose mode were not shown when operating on zero length files.

    An attempt to compress zero length files resulted in an unexpected return code.

    Users of ncompress are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-1168
    RHSA-2006:0663
    RHSA-2006:0663-01
    RHSA-2006:0663-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND ncompress is earlier than 0:4.2.4-39.rhel3
  • AND ncompress is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND ncompress is earlier than 0:4.2.4-43.rhel4
  • AND ncompress is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND ncompress is earlier than 0:4.2.4-39.rhel3
  • AND ncompress is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND ncompress is earlier than 0:4.2.4-43.rhel4
  • AND ncompress is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND ncompress is earlier than 0:4.2.4-43.rhel4
  • AND ncompress is signed with Red Hat redhatrelease2 key
  • BACK