Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: 200306-05 Moderate: Gzip Insecure Temporary Files Threat

gentoo
Calendar Grey June 14, 2003
Dist Gentoo Esm H88
Gentoo Linux Security Bulletin regarding gzip vulnerable temporary files. It is recommended to update in order to safeguard against potential data losses.
znew and gzexe in the gzip package allows local users to overwritearbitrary files via a symlink attack on temporary files.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-05
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
znew and gzexe in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
SOLUTION
It is recommended that all Gentoo Linux users who are running sys-apps/gzip upgrade to gzip-1.3.3-r2 as follows
emerge sync emerge gzip emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

PACKAGE : gzip
SUMMARY : insecure temporary files
DATE : 2003-06-14 16:40 UTC
EXPLOIT : local
VERSIONS AFFECTED : =gzip-1.3.3-r2
CVE : CVE-1999-1332 CAN-2003-0367

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here