Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian: DSA 588-1 Critical: Gzip Local File Overwrite Threat

debian
Calendar Grey November 8, 2004
Debian Logo
Debian security notice DSA 589-1 warns of a critical tar vulnerability enabling unauthorized local file access via symlink exploitation. Users should update immediately
Trustix developers discovered insecure temporary file creation in supplemental scripts in the gzip package which may allow local users to overwrite files via a symlink attack.

Summary

Trustix developers discovered insecure temporary file creation in
supplemental scripts in the gzip package which may allow local usersto overwrite files via a symlink attack.

For the stable distribution (woody) these problems have been fixed in
version 1.3.2-3woody3.

The unstable distribution (sid) is not affected by these problems.

We recommend that you upgrade your gzip package.


Upgrade Instructions
--------------------

wget url
will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
--------------------------------

Source archives:


Size/MD5 checksum: 577 3b5fd05de61de0a41973facf1edc6692

Size/MD5 checks...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: gzip
CVE ID: CAN-2004-0970

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here