|
Family: Red Hat Local Security Checks --> Category: infos
RHSA-2006-0667: gzip Vulnerability Scan
Vulnerability Scan Summary Check for the version of the gzip packages
Detailed Explanation for this Vulnerability Test
Updated gzip packages that fix several security issues are now available
for Red Hat Enterprise Linux.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The gzip package contains the GNU gzip data compression program.
Tavis Ormandy of the Google Security Team discovered two denial of service
flaws in the way gzip expanded archive files. If a victim expanded a
specially crafted archive, it could cause the gzip executable to hang or
crash. (CVE-2006-4334, CVE-2006-4338)
Tavis Ormandy of the Google Security Team discovered several code execution
flaws in the way gzip expanded archive files. If a victim expanded a
specially crafted archive, it could cause the gzip executable to crash or
execute arbitrary code. (CVE-2006-4335, CVE-2006-4336, CVE-2006-4337)
Users of gzip should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to these issues.
Solution : http://rhn.redhat.com/errata/RHSA-2006-0667.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|