First published: Mon May 02 2022(Updated: )
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.<br>Security Fix(es):<br><li> gzip: arbitrary-file-write vulnerability (CVE-2022-1271)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gzip | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip-debuginfo | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip-debugsource | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip-debuginfo | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip-debugsource | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip-debuginfo | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip-debugsource | <1.9-10.el8_2 | 1.9-10.el8_2 |
redhat/gzip | <1.9-10.el8_2.aa | 1.9-10.el8_2.aa |
redhat/gzip-debuginfo | <1.9-10.el8_2.aa | 1.9-10.el8_2.aa |
redhat/gzip-debugsource | <1.9-10.el8_2.aa | 1.9-10.el8_2.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1665 is classified as important.
To fix RHSA-2022:1665, you should update the gzip package to version 1.9-10.el8_2 or later.
The RHSA-2022:1665 vulnerability affects the gzip data compression utility used in various Red Hat packages.
Yes, the RHSA-2022:1665 vulnerability involves arbitrary-file access due to flaws in the gzip package.
RHSA-2022:1665 impacts systems running specific versions of the gzip package on Red Hat Enterprise Linux 8.