First published: Tue Apr 26 2022(Updated: )
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.<br>Security Fix(es):<br><li> gzip: arbitrary-file-write vulnerability (CVE-2022-1271)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gzip | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip-debuginfo | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip-debugsource | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip-debuginfo | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip-debugsource | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip-debuginfo | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip-debugsource | <1.9-13.el8_5 | 1.9-13.el8_5 |
redhat/gzip | <1.9-13.el8_5.aa | 1.9-13.el8_5.aa |
redhat/gzip-debuginfo | <1.9-13.el8_5.aa | 1.9-13.el8_5.aa |
redhat/gzip-debugsource | <1.9-13.el8_5.aa | 1.9-13.el8_5.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1537 is classified as important.
To fix RHSA-2022:1537, update the gzip package to version 1.9-13.el8_5 or later.
The affected packages include gzip, gzip-debuginfo, and gzip-debugsource versions prior to 1.9-13.el8_5.
RHSA-2022:1537 addresses arbitrary file overwrite vulnerabilities in the gzip utility.
Systems utilizing the gzip package prior to version 1.9-13.el8_5 are impacted by RHSA-2022:1537.