Oval Definition:oval:com.redhat.rhsa:def:20100061
Revision Date:2010-01-20Version:638
Title:RHSA-2010:0061: gzip security update (Moderate)
Description:The gzip package provides the GNU gzip data compression program.

  • An integer underflow flaw, leading to an array index error, was found in the way gzip expanded archive files compressed with the Lempel-Ziv-Welch (LZW) compression algorithm. If a victim expanded a specially-crafted archive, it could cause gzip to crash or, potentially, execute arbitrary code with the privileges of the user running gzip. This flaw only affects 64-bit systems. (CVE-2010-0001)

    Red Hat would like to thank Aki Helin of the Oulu University Secure Programming Group for responsibly reporting this flaw.

    Users of gzip should upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-0001
    RHSA-2010:0061
    RHSA-2010:0061-02
    RHSA-2010:0061-02
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND gzip is earlier than 0:1.3.3-15.rhel3
  • AND gzip is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND gzip is earlier than 0:1.3.3-18.el4_8.1
  • AND gzip is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND gzip is earlier than 0:1.3.5-11.el5_4.1
  • AND gzip is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND gzip is earlier than 0:1.3.3-18.el4_8.1
  • AND gzip is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND gzip is earlier than 0:1.3.5-11.el5_4.1
  • AND gzip is signed with Red Hat redhatrelease2 key
  • BACK