Updated unzip and tar packages fix vulnerabilities
| Advisory: | RHSA-2002:096-24 |
|---|---|
| Type: | Security Advisory |
| Severity: | N/A |
| Issued on: | 2002-05-20 |
| Last updated on: | 2002-09-18 |
| Affected Products: | Red Hat Linux 6.2 Red Hat Linux 7.0 Red Hat Linux 7.1 Red Hat Linux 7.2 Red Hat Linux 7.3 |
| CVEs (cve.mitre.org): |
CVE-2001-1267 CVE-2001-1268 CVE-2001-1269 CVE-2002-0399 CVE-2002-1216 |
Details
The unzip and tar utilities contain vulnerabilities which can allow
arbitrary files to be overwritten during archive extraction.
The unzip and tar utilities are used for manipulating archives, which
are multiple files stored inside of a single file.
A directory traversal vulnerability in unzip version 5.42 and earlier,
as well as GNU tar 1.13.19 and earlier, allows attackers to overwrite
arbitrary files during archive extraction via a ".." (dot dot) in an
extracted filename. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2001-1267 and CAN-2001-1268 to
this issue.
In addition, unzip version 5.42 and earlier also allows attackers to
overwrite arbitrary files during archive extraction via filenames in the
archive that begin with the "/" (slash) character. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2001-1269 to this issue.
During testing of the fix to GNU tar, it was discovered that GNU tar
1.13.25 was still vulnerable to a modified version of the same problem. Red
Hat has provided a patch to tar 1.3.25 to correct this problem. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2002-0399 to this issue.
Users of unzip and tar are advised to upgrade to these errata packages,
containing unzip version 5.50 (for Red Hat Linux 6.2, 7, 7.1, and 7.2) and
a patched version of GNU tar 1.13.25 (for Red Hat Linux 6.2, 7, 7.1, 7.2,
and 7.3), which are not vulnerable to these issues.
Important Note: For users of Red Hat Linux 6.2 and 7 only, these errata
packages change one of the command line options for tar. Previously the
'-I' option was used to enable bzip2 compression, while in these errata
packages the option has changed to '-j'.
Solution
relevant to your system have been applied.
To update all RPMs for your particular architecture, run:
rpm -Fvh [filenames]
where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains
the desired RPMs.
Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:
up2date
This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.
Updated packages
| Red Hat Linux 6.2 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-1.6/SRPMS/tar-1.13.25-1.6.src.rpm Missing file |
MD5: bb301fb39190fdfbc17f0c8c172f920a |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-1.62/SRPMS/unzip-5.50-1.62.src.rpm Missing file |
MD5: 5dcc6924500aa5f7858ae266a5f8998b |
| Alpha: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-1.6/alpha/tar-1.13.25-1.6.alpha.rpm Missing file |
MD5: fef15632b9bcf32d14356654134c53c5 |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-1.62/alpha/unzip-5.50-1.62.alpha.rpm Missing file |
MD5: 2b3d7a3a5ec06ced671e8e338f3e6c4e |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-1.6/i386/tar-1.13.25-1.6.i386.rpm Missing file |
MD5: 81004b0dd856b5e68847d7b3c98df7fc |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-1.62/i386/unzip-5.50-1.62.i386.rpm Missing file |
MD5: 9bae9f9eb1f4465aef6d8e88fc651cbd |
| Sparc: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-1.6/sparc/tar-1.13.25-1.6.sparc.rpm Missing file |
MD5: ac09b26f328364bcbffef59d92b7544c |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-1.62/sparc/unzip-5.50-1.62.sparc.rpm Missing file |
MD5: a68f875f73dc8551a65018ab46bb28c3 |
| Red Hat Linux 7.0 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/SRPMS/tar-1.13.25-4.7.1.src.rpm Missing file |
MD5: 0b54c5bd9400cdedd26bdf64d9e69a80 |
| unzip-5.50-2.src.rpm File outdated by: RHSA-2003:199 |
MD5: 2c1387cc558515919e2585b5708fd219 |
| Alpha: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/alpha/tar-1.13.25-4.7.1.alpha.rpm Missing file |
MD5: c12063f58936ceb68848530b8e69d304 |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-2/alpha/unzip-5.50-2.alpha.rpm Missing file |
MD5: 25e5cb389451c393a58c8e2755180925 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/i386/tar-1.13.25-4.7.1.i386.rpm Missing file |
MD5: fb5f89ea78abb60d50424dda0ac0db79 |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-2/i386/unzip-5.50-2.i386.rpm Missing file |
MD5: 877f4fda6198e604b539fb85664a3aad |
| Red Hat Linux 7.1 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/SRPMS/tar-1.13.25-4.7.1.src.rpm Missing file |
MD5: 0b54c5bd9400cdedd26bdf64d9e69a80 |
| unzip-5.50-2.src.rpm File outdated by: RHSA-2003:199 |
MD5: 2c1387cc558515919e2585b5708fd219 |
| Alpha: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/alpha/tar-1.13.25-4.7.1.alpha.rpm Missing file |
MD5: c12063f58936ceb68848530b8e69d304 |
| ftp://updates.redhat.com/rhn/repository/NULL/unzip/5.50-2/alpha/unzip-5.50-2.alpha.rpm Missing file |
MD5: 25e5cb389451c393a58c8e2755180925 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/i386/tar-1.13.25-4.7.1.i386.rpm Missing file |
MD5: fb5f89ea78abb60d50424dda0ac0db79 |
| unzip-5.50-2.i386.rpm File outdated by: RHSA-2003:199 |
MD5: 877f4fda6198e604b539fb85664a3aad |
| IA-64: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/ia64/tar-1.13.25-4.7.1.ia64.rpm Missing file |
MD5: a8aa3558565507d16f8cb91b6fed5d88 |
| ftp://updates.redhat.com/rhn/private/redhat-linux-as-2.1-IPF/RPMS/unzip-5.50-2.ia64.rpm Missing file |
MD5: f233de217386e5913b6460d22022dbb6 |
| Red Hat Linux 7.2 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/SRPMS/tar-1.13.25-4.7.1.src.rpm Missing file |
MD5: 0b54c5bd9400cdedd26bdf64d9e69a80 |
| unzip-5.50-2.src.rpm File outdated by: RHSA-2003:199 |
MD5: 2c1387cc558515919e2585b5708fd219 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/i386/tar-1.13.25-4.7.1.i386.rpm Missing file |
MD5: fb5f89ea78abb60d50424dda0ac0db79 |
| unzip-5.50-2.i386.rpm File outdated by: RHSA-2003:199 |
MD5: 877f4fda6198e604b539fb85664a3aad |
| IA-64: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/ia64/tar-1.13.25-4.7.1.ia64.rpm Missing file |
MD5: a8aa3558565507d16f8cb91b6fed5d88 |
| unzip-5.50-2.ia64.rpm File outdated by: RHSA-2003:199 |
MD5: f233de217386e5913b6460d22022dbb6 |
| Red Hat Linux 7.3 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/SRPMS/tar-1.13.25-4.7.1.src.rpm Missing file |
MD5: 0b54c5bd9400cdedd26bdf64d9e69a80 |
| unzip-5.50-2.src.rpm File outdated by: RHSA-2003:199 |
MD5: 2c1387cc558515919e2585b5708fd219 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/tar/1.13.25-4.7.1/i386/tar-1.13.25-4.7.1.i386.rpm Missing file |
MD5: fb5f89ea78abb60d50424dda0ac0db79 |
| unzip-5.50-2.i386.rpm File outdated by: RHSA-2003:199 |
MD5: 877f4fda6198e604b539fb85664a3aad |
References
https://www.redhat.com/security/data/cve/CVE-2001-1268.html
https://www.redhat.com/security/data/cve/CVE-2001-1269.html
https://www.redhat.com/security/data/cve/CVE-2002-0399.html
https://www.redhat.com/security/data/cve/CVE-2002-1216.html
http://online.securityfocus.com/archive/1/196445
Keywords
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/