Oval Definition:oval:com.redhat.rhsa:def:20070203
Revision Date:2008-03-20Version:640
Title:RHSA-2007:0203: unzip security and bug fix update (Low)
Description:The unzip utility is used to list, test, or extract files from a zip archive.

  • A race condition was found in Unzip. Local users could use this flaw to modify permissions of arbitrary files via a hard link attack on a file while it was being decompressed (CVE-2005-2475)

  • A buffer overflow was found in Unzip command line argument handling. If a user could be tricked into running Unzip with a specially crafted long file name, an attacker could execute arbitrary code with that user's privileges. (CVE-2005-4667)

    As well, this update adds support for files larger than 2GB.

    All users of unzip should upgrade to these updated packages, which contain backported patches that resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2005-2475
    CVE-2005-4667
    RHSA-2007:0203
    RHSA-2007:0203-02
    RHSA-2007:0203-02
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND unzip is earlier than 0:5.51-9.EL4.5
  • AND unzip is signed with Red Hat redhatrelease2 key
  • BACK