First published: Tue Sep 19 2006(Updated: )
The gzip package contains the GNU gzip data compression program.<br>Tavis Ormandy of the Google Security Team discovered two denial of service<br>flaws in the way gzip expanded archive files. If a victim expanded a<br>specially crafted archive, it could cause the gzip executable to hang or<br>crash. (CVE-2006-4334, CVE-2006-4338)<br>Tavis Ormandy of the Google Security Team discovered several code execution<br>flaws in the way gzip expanded archive files. If a victim expanded a<br>specially crafted archive, it could cause the gzip executable to crash or<br>execute arbitrary code. (CVE-2006-4335, CVE-2006-4336, CVE-2006-4337)<br>Users of gzip should upgrade to these updated packages, which contain a<br>backported patch and is not vulnerable to these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gzip | <1.3.3-16.rhel4 | 1.3.3-16.rhel4 |
redhat/gzip | <1.3.3-16.rhel4 | 1.3.3-16.rhel4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2006:0667 is classified as moderate due to the denial of service vulnerabilities.
To fix RHSA-2006:0667, update the gzip package to version 1.3.3-16.rhel4 or later.
RHSA-2006:0667 affects Red Hat Enterprise Linux 4 systems that utilize the gzip package.
RHSA-2006:0667 describes denial of service vulnerabilities that occur when expanding specially crafted gzip archive files.
The vulnerabilities in RHSA-2006:0667 were discovered by Tavis Ormandy of the Google Security Team.