Lucene search

K
redhatRedHatRHSA-2010:0061
HistoryJan 20, 2010 - 12:00 a.m.

(RHSA-2010:0061) Moderate: gzip security update

2010-01-2000:00:00
access.redhat.com
17

EPSS

0.061

Percentile

93.6%

The gzip package provides the GNU gzip data compression program.

An integer underflow flaw, leading to an array index error, was found in
the way gzip expanded archive files compressed with the Lempel-Ziv-Welch
(LZW) compression algorithm. If a victim expanded a specially-crafted
archive, it could cause gzip to crash or, potentially, execute arbitrary
code with the privileges of the user running gzip. This flaw only affects
64-bit systems. (CVE-2010-0001)

Red Hat would like to thank Aki Helin of the Oulu University Secure
Programming Group for responsibly reporting this flaw.

Users of gzip should upgrade to this updated package, which contains a
backported patch to correct this issue.