RHSA-2006:0663: ncompress security update
The ncompress package contains file compression and decompressionutilities, which are compatible with the original UNIX compress utility (.Zfile extensions).Tavis Ormandy of the Google Security Team discovered a lack of boundschecking in ncompress. An attacker could create a carefully crafted filethat could execute arbitrary code if uncompressed by a victim. (CVE-2006-1168)In addition, two bugs that affected Red Hat Enterprise Linux 4 ncompresspackages were fixed: The display statistics and compression results in verbose mode were not shown when operating on zero length files. An attempt to compress zero length files resulted in an unexpected return code.Users of ncompress are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2006:0663?
The severity of RHSA-2006:0663 is classified as important due to an attacker potentially exploiting a lack of bounds checking in ncompress.
How do I fix RHSA-2006:0663?
To fix RHSA-2006:0663, update the ncompress package to version 4.2.4-43.rhel4 or later.
What vulnerability does RHSA-2006:0663 address?
RHSA-2006:0663 addresses a vulnerability related to a lack of bounds checking in the ncompress package.
Who discovered the vulnerability in RHSA-2006:0663?
The vulnerability in RHSA-2006:0663 was discovered by Tavis Ormandy of the Google Security Team.
What is the affected software in RHSA-2006:0663?
The affected software in RHSA-2006:0663 is the ncompress package version prior to 4.2.4-43.rhel4.