Solution
Please Install the Updated Packages.
Insight
The unzip utility is used to list, test, or extract files from a zip archive.
An invalid pointer flaw was found in unzip. If a user ran unzip on a specially crafted file, an attacker could execute arbitrary code with that user's privileges. (CVE-2008-0888)
Red Hat would like to thank Tavis Ormandy of the Google Security Team for reporting this issue.
All unzip users are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue.
Affected
unzip on Red Hat Enterprise Linux AS (Advanced Server) version 2.1, Red Hat Enterprise Linux ES version 2.1,
Red Hat Enterprise Linux WS version 2.1,
Red Hat Enterprise Linux AS version 3,
Red Hat Enterprise Linux ES version 3,
Red Hat Enterprise Linux WS version 3
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-0888 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities