Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66758
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2010:0061
Summary:NOSUMMARY
Description:Description:
The remote host is missing updates announced in
advisory RHSA-2010:0061.

The gzip package provides the GNU gzip data compression program.

An integer underflow flaw, leading to an array index error, was found in
the way gzip expanded archive files compressed with the Lempel-Ziv-Welch
(LZW) compression algorithm. If a victim expanded a specially-crafted
archive, it could cause gzip to crash or, potentially, execute arbitrary
code with the privileges of the user running gzip. This flaw only affects
64-bit systems. (CVE-2010-0001)

Red Hat would like to thank Aki Helin of the Oulu University Secure
Programming Group for responsibly reporting this flaw.

Users of gzip should upgrade to this updated package, which contains a
backported patch to correct this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2010-0061.html
http://www.redhat.com/security/updates/classification/#moderate

Risk factor : High

CVSS Score:
6.8

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-0001
1023490
http://securitytracker.com/id?1023490
38220
http://secunia.com/advisories/38220
38223
http://secunia.com/advisories/38223
38225
http://secunia.com/advisories/38225
38232
http://secunia.com/advisories/38232
40551
http://secunia.com/advisories/40551
40655
http://secunia.com/advisories/40655
40689
http://secunia.com/advisories/40689
61869
http://www.osvdb.org/61869
ADV-2010-0185
http://www.vupen.com/english/advisories/2010/0185
ADV-2010-1796
http://www.vupen.com/english/advisories/2010/1796
ADV-2010-1872
http://www.vupen.com/english/advisories/2010/1872
APPLE-SA-2010-11-10-1
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
DSA-1974
http://www.debian.org/security/2010/dsa-1974
DSA-2074
http://www.debian.org/security/2010/dsa-2074
HPSBMA02554
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083
MDVSA-2010:019
http://www.mandriva.com/security/advisories?name=MDVSA-2010:019
MDVSA-2010:020
http://www.mandriva.com/security/advisories?name=MDVSA-2010:020
MDVSA-2011:152
http://www.mandriva.com/security/advisories?name=MDVSA-2011:152
RHSA-2010:0061
http://www.redhat.com/support/errata/RHSA-2010-0061.html
RHSA-2010:0095
https://rhn.redhat.com/errata/RHSA-2010-0095.html
SSRT100018
SUSE-SA:2010:008
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html
USN-889-1
http://www.ubuntu.com/usn/USN-889-1
http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468f
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://ncompress.sourceforge.net/#status
http://savannah.gnu.org/forum/forum.php?forum_id=6153
http://support.apple.com/kb/HT4435
https://bugzilla.redhat.com/show_bug.cgi?id=554418
oval:org.mitre.oval:def:10546
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10546
oval:org.mitre.oval:def:7511
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7511
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.