Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 589
Alerts This Week
Warning Icon 1 589

Gentoo Linux GLSA 200411-16 Normal: Zip Buffer Overflow Risk

gentoo
Calendar Grey November 9, 2004
Scroller Gentoo
Ubuntu advisory USN-2009-144 highlights a critical vulnerability in zip software leading to potential code execution. Immediate patching suggested.
zip contains a buffer overflow when creating a ZIP archive of files with very long path names

Summary

Gentoo Linux Security Advisory GLSA 200411-16 https://security.gentoo.org/ Severity: Normal Title: zip: Path name buffer overflow Date: November 09, 2004 Bugs: #70227 ID: 200411-16

Synopsis ======= zip contains a buffer overflow when creating a ZIP archive of files with very long path names. This could lead to the execution of arbitrary code.
Background ========= zip is a compression and file packaging utility.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/zip <= 2.3-r3 >= 2.3-r4
========== zip does not check the resulting path length when doing recursive folder compression.
Impact ===== An attacker could exploit this by enticing anoth...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround