Family: Slackware Local Security Checks --> Category: infos
SSA-2005-121-01 infozip Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
New infozip (zip/unzip) packages are available for Slackware 8.1, 9.0,
9.1, 10.0, 10.1, and -current to fix security issues.
- From the www.info-zip.org site:
Zip 2.3 and (presumably) all previous versions have a buffer-
overrun vulnerability relating to deep directory paths that could
potentially lead to local privilege escalation (e.g., in the case of
automated, Zip-based backups). See the FAQ page for details.
All versions of UnZip through 5.50 have a number of directory-
traversal vulnerabilities, and version 5.50 also has a textmode data-
corruption bug that affects 16-bit ports such as MS-DOS. See the FAQ
page for details.
Click HERE for more information and discussions on this network vulnerability scan.