LWN.net Logo

gzip: arbitrary code execution

Package(s):gzip CVE #(s):CVE-2010-0001
Created:January 20, 2010 Updated:October 17, 2011
Description:

From the Red Hat advisory:

An integer underflow flaw, leading to an array index error, was found in the way gzip expanded archive files compressed with the Lempel-Ziv-Welch (LZW) compression algorithm. If a victim expanded a specially-crafted archive, it could cause gzip to crash or, potentially, execute arbitrary code with the privileges of the user running gzip. This flaw only affects 64-bit systems. (CVE-2010-0001)

Alerts:
Mandriva MDVSA-2011:152 2011-10-17
Debian DSA-2074-1 2010-07-21
Pardus 2010-86 2010-06-24
rPath rPSA-2010-0013-1 2010-03-07
CentOS CESA-2010:0061 2010-01-22
Red Hat RHSA-2010:0061-02 2010-01-20
Ubuntu USN-889-1 2010-01-20
Mandriva MDVSA-2010:020 2010-01-20
Mandriva MDVSA-2010:019 2010-01-20
Debian DSA-1974-1 2010-01-20
CentOS CESA-2010:0061 2010-01-20
CentOS CESA-2010:0061 2010-01-20
Fedora FEDORA-2010-0884 2010-01-22
Slackware SSA:2010-060-03 2010-03-02
Fedora FEDORA-2010-0964 2010-01-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds