Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
98

Red Hat Enterprise Linux RHSA-2004:634-01 Critical: Zip Buffer Overflow

An updated zip package that fixes a buffer overflow vulnerability is now available.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated zip package fixes security issue Advisory ID: RHSA-2004:634-01 Advisory URL: https://access.redhat.com/errata/RHSA-2004:634.html Issue date: 2004-12-16 Updated on: 2004-12-16 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-1010 ---------------------------------------------------------------------1. Summary: An updated zip package that fixes a buffer overflow vulnerability is now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: The zip program is an archiving utility which can create ZIP-compatible archives. A buffer overflow bug has been discovered in zip when handling long file names. An attacker could create a specially crafted path which could cause zip to crash or execute arbitrary instructions. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1010 to this issue. Users of zip should upgrade to this updated package, which contains backported patches and is not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information onhow to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info): 138228 - CAN-2004-1010 buffer overflow when creating archive containing very long filenames. 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: b062c345c3d6c56ed1c042145643c8c8 zip-2.3-10.1.src.rpm i386: a06a150a5652173a8309cca26cc3c70f zip-2.3-10.1.i386.rpm ia64: 6cab305bdaca789e53e760184050fab9 zip-2.3-10.1.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: b062c345c3d6c56ed1c042145643c8c8 zip-2.3-10.1.src.rpm ia64: 6cab305bdaca789e53e760184050fab9 zip-2.3-10.1.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: b062c345c3d6c56ed1c042145643c8c8 zip-2.3-10.1.src.rpm i386: a06a150a5652173a8309cca26cc3c70f zip-2.3-10.1.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: b062c345c3d6c56ed1c042145643c8c8 zip-2.3-10.1.src.rpm i386: a06a150a5652173a8309cca26cc3c70f zip-2.3-10.1.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: aa360ac25cf50772fd010cf2d1d91db7 zip-2.3-16.1.src.rpm i386: 41fec60bfbbca5266e4bbff55f42031a zip-2.3-16.1.i386.rpm ia64: 0b8464b40ec9d081dd36ab9d699a4c1c zip-2.3-16.1.ia64.rpm ppc: 787ad3673b90f4fcb0d47c815ca984f6 zip-2.3-16.1.ppc.rpm s390: 97c709a606b3cec173833833b24c704b zip-2.3-16.1.s390.rpm s390x: 4d1f10e6b1e4247cb037eb42c8fcc796 zip-2.3-16.1.s390x.rpm x86_64: 1ed34c119e86a0c739c1c5bb706ffb69 zip-2.3-16.1.x86_64.rpm Red Hat Desktop version 3: SRPMS: aa360ac25cf50772fd010cf2d1d91db7 zip-2.3-16.1.src.rpm i386: 41fec60bfbbca5266e4bbff55f42031a zip-2.3-16.1.i386.rpm x86_64: 1ed34c119e86a0c739c1c5bb706ffb69 zip-2.3-16.1.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: aa360ac25cf50772fd010cf2d1d91db7 zip-2.3-16.1.src.rpm i386: 41fec60bfbbca5266e4bbff55f42031a zip-2.3-16.1.i386.rpm ia64: 0b8464b40ec9d081dd36ab9d699a4c1c zip-2.3-16.1.ia64.rpm x86_64: 1ed34c119e86a0c739c1c5bb706ffb69 zip-2.3-16.1.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: aa360ac25cf50772fd010cf2d1d91db7 zip-2.3-16.1.src.rpm i386: 41fec60bfbbca5266e4bbff55f42031a zip-2.3-16.1.i386.rpm ia64: 0b8464b40ec9d081dd36ab9d699a4c1c zip-2.3-16.1.ia64.rpm x86_64: 1ed34c119e86a0c739c1c5bb706ffb69 zip-2.3-16.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from 7. References: https://www.cve.org/CVERecord?id=CAN-2004-1010 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Released new zip package version to fix buffer overflow vulnerability affecting Red Hat Enterprise Linux platforms.. Red Hat Zip Security Fix, Buffer Overflow Update, Linux Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 17, 2004 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here