CVE-2001-1228: Buffer Overflow
Published Nov 18, 2001
·Updated
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
Affected Software
3 affected components
GNU gzip=1.2.4
GNU gzip=1.2.4a
GNU gzip=1.3
Remediation
Patch Available
Event History
Nov 18, 2001
CVE Published
05:00 AM
Apr 12, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1228?
CVE-2001-1228 is considered to have a critical severity level due to the potential for remote code execution.
2
How do I fix CVE-2001-1228?
To fix CVE-2001-1228, upgrade gzip to a version that is not vulnerable, such as 1.3.3 or later.
3
What software is affected by CVE-2001-1228?
CVE-2001-1228 affects GNU gzip versions 1.2.4, 1.2.4a, and 1.3.
4
Can CVE-2001-1228 be exploited remotely?
Yes, CVE-2001-1228 can potentially be exploited remotely if gzip is run on an FTP server.
5
What is the impact of CVE-2001-1228 on systems?
The impact of CVE-2001-1228 is that it may allow attackers to execute arbitrary code on the affected system.