Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian 11 DSA 752-1 Moderate: Gzip Local And Remote Threats Fix

debian
Calendar Grey July 11, 2005
Debian Logo
Debian has issued an update for the gzip package, fixing several vulnerabilities that can be exploited both locally and remotely. Check the changes and follow the suggested mitigation steps
Two problems have been discovered in gzip, the GNU compression utility.

Summary


Imran Ghory discovered a race condition in the permissions setting
code in gzip. When decompressing a file in a directory an
attacker has access to, gunzip could be tricked to set the file
permissions to a different file the user has permissions to.

CAN-2005-1228

Ulf Härnhammar discovered a path traversal vulnerability in
gunzip. When gunzip is used with the -N option an attacker could
this vulnerability to create files in an arbitrary directory with
the permissions of the user.

For the oldstable distribution (woody) these problems have been fixed in
version 1.3.2-3woody5.

For the stable distribution (sarge) these problems have been fixed in
version 1.3.5-10.

For the unstable distribution (sid) these problems have been fixed in
version 1.3.5-10.

We recommend that you upgrade your gzip package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here