the internet's safety

rPSA-2006-0170-1.txt

rPSA-2006-0170-1.txt
Posted Sep 27, 2006
Site security.rpath.com

rPath Security Advisory: 2006-0170-1 - Previous versions of the gzip package contain multiple vulnerabilities that enable user-complicit unauthorized access when a user attempts to gunzip intentionally malformed gzip files. Some network services will automatically run the gunzip program in some contexts, which may then enable direct unauthorized access to the user account that provides the network service.

tags | advisory, vulnerability
MD5 | bc9030050a66cde7562425954c30e607

rPSA-2006-0170-1.txt

Change Mirror Download
rPath Security Advisory: 2006-0170-1
Published: 2006-09-19
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
Indirect User Deterministic Unauthorized Access
Updated Versions:
gzip=/conary.rpath.com@rpl:devel//1/1.3.5-4-0.1

References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4334
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4335
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4336
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4337
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4338
https://issues.rpath.com/browse/RPL-615

Description:
Previous versions of the gzip package contain multiple vulnerabilities
that enable user-complicit unauthorized access when a user attempts to
gunzip intentionally malformed gzip files. Some network services will
automatically run the gunzip program in some contexts, which may then
enable direct unauthorized access to the user account that provides
the network service.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close