Low: unzip security and bug fix update. Date: Mon, 14 May 2007 15:51:37 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for unzip on SL4.x i386/x86_64 Comments: To: scientific Synopsis: Low: unzip security and bug fix update Issue date: 2007-05-01 CVE Names: CVE-2005-2475 CVE-2005-4667 A race condition was found in Unzip. Local users could use this flaw to modify permissions of arbitrary files via a hard link attack on a file while it was being decompressed (CVE-2005-2475) A buffer overflow was found in Unzip command line argument handling. If a user could be tricked into running Unzip with a specially crafted long file name, an attacker could execute arbitrary code with that user's privileges. (CVE-2005-4667) SRPMS: unzip-5.51-9.EL4.5.src.rpm i386: unzip-5.51-9.EL4.5.i386.rpm x86_64: unzip-5.51-9.EL4.5.x86_64.rpm . Stay informed about recent unzip vulnerabilities in Scientific Linux that could compromise system integrity and update your systems to mitigate security risks. unzip update, Scientific Linux security, file permissions, security bug. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.