_______________________________________________________________________
Package : gzip
Date : January 20, 2010
Affected: Corporate 4.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in gzip:
An integer underflow leading to array index error was found in the
way gzip used to decompress files / archives, compressed with the
Lempel-Ziv-Welch (LZW) compression algorithm. A remote attacker could
provide a specially-crafted LZW compressed gzip archive, which once
decompressed by a local, unsuspecting user would lead to gzip crash,
or, potentially to arbitrary code execution with the privileges of
the user running gzip (CVE-2010-0001).
The updated packages have been patched to correct thies issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2010-0001
_______________________________________________________________________