Oval Definition:oval:com.redhat.rhsa:def:20080196
Revision Date:2008-03-18Version:633
Title:RHSA-2008:0196: unzip security update (Moderate)
Description:The unzip utility is used to list, test, or extract files from a zip archive.

  • An invalid pointer flaw was found in unzip. If a user ran unzip on a specially crafted file, an attacker could execute arbitrary code with that user's privileges. (CVE-2008-0888)

    Red Hat would like to thank Tavis Ormandy of the Google Security Team for reporting this issue.

    All unzip users are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-0888
    RHSA-2008:0196
    RHSA-2008:0196-01
    RHSA-2008:0196-01
    Platform(s):Red Hat Enterprise Linux 3
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND unzip is earlier than 0:5.50-36.EL3
  • AND unzip is signed with Red Hat master key
  • BACK