Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Gentoo Linux GLSA 200411-16 Normal: Zip Buffer Overflow Risk

gentoo
Calendar Grey November 9, 2004
Dist Gentoo Esm H88
Ubuntu advisory USN-2009-144 highlights a critical vulnerability in zip software leading to potential code execution. Immediate patching suggested.
zip contains a buffer overflow when creating a ZIP archive of files with very long path names

Summary

Gentoo Linux Security Advisory GLSA 200411-16 https://security.gentoo.org/ Severity: Normal Title: zip: Path name buffer overflow Date: November 09, 2004 Bugs: #70227 ID: 200411-16

Synopsis ======= zip contains a buffer overflow when creating a ZIP archive of files with very long path names. This could lead to the execution of arbitrary code.
Background ========= zip is a compression and file packaging utility.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/zip <= 2.3-r3 >= 2.3-r4
========== zip does not check the resulting path length when doing recursive folder compression.
Impact ===== An attacker could exploit this by enticing anoth...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3579797_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here