The unzip and tar utilities contain vulnerabilities which can allow
arbitrary files to be overwritten during archive extraction.
The unzip and tar utilities are used for manipulating archives, which
are multiple files stored inside of a single file.
A directory traversal vulnerability in unzip version 5.42 and earlier,
as well as GNU tar 1.13.19 and earlier, allows attackers to overwrite
arbitrary files during archive extraction via a ".." (dot dot) in an
extracted filename. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2001-1267 and CAN-2001-1268 to
this issue.
In addition, unzip version 5.42 and earlier also allows attackers to
overwrite arbitrary files during archive extraction via filenames in the
archive that begin with the "/" (slash) character. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2001-1269 to this issue.
During testing of the fix to GNU tar, it was discovered that GNU tar
1.13.25 was still vulnerable to a modified version of the same problem. Red
Hat has provided a patch to tar 1.3.25 to correct this problem. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2002-0399 to this issue.
Users of unzip and tar are advised to upgrade to these errata packages,
containing unzip version 5.50 (for Red Hat Linux 6.2, 7, 7.1, and 7.2) and
a patched version of GNU tar 1.13.25 (for Red Hat Linux 6.2, 7, 7.1, 7.2,
and 7.3), which are not vulnerable to these issues.
Important Note: For users of Red Hat Linux 6.2 and 7 only, these errata
packages change one of the command line options for tar. Previously the
'-I' option was used to enable bzip2 compression, while in these errata
packages the option has changed to '-j'.
| Red Hat Linux 6.2 |
|
| SRPMS: |
ftp://updates.redhat.com/6.2/en/os/SRPMS/tar-1.13.25-1.6.src.rpm
Missing file |
bb301fb39190fdfbc17f0c8c172f920a |
ftp://updates.redhat.com/6.2/en/os/SRPMS/unzip-5.50-1.62.src.rpm
Missing file |
5dcc6924500aa5f7858ae266a5f8998b |
| |
| Alpha: |
ftp://updates.redhat.com/6.2/en/os/alpha/tar-1.13.25-1.6.alpha.rpm
Missing file |
fef15632b9bcf32d14356654134c53c5 |
ftp://updates.redhat.com/6.2/en/os/alpha/unzip-5.50-1.62.alpha.rpm
Missing file |
2b3d7a3a5ec06ced671e8e338f3e6c4e |
| |
| IA-32: |
ftp://updates.redhat.com/6.2/en/os/i386/tar-1.13.25-1.6.i386.rpm
Missing file |
81004b0dd856b5e68847d7b3c98df7fc |
ftp://updates.redhat.com/6.2/en/os/i386/unzip-5.50-1.62.i386.rpm
Missing file |
9bae9f9eb1f4465aef6d8e88fc651cbd |
| |
| Sparc: |
ftp://updates.redhat.com/6.2/en/os/sparc/tar-1.13.25-1.6.sparc.rpm
Missing file |
ac09b26f328364bcbffef59d92b7544c |
ftp://updates.redhat.com/6.2/en/os/sparc/unzip-5.50-1.62.sparc.rpm
Missing file |
a68f875f73dc8551a65018ab46bb28c3 |
| |
| Red Hat Linux 7.0 |
|
| SRPMS: |
ftp://updates.redhat.com/7.0/en/os/SRPMS/tar-1.13.25-4.7.1.src.rpm
Missing file |
0b54c5bd9400cdedd26bdf64d9e69a80 |
unzip-5.50-2.src.rpm
File outdated by: RHSA-2003:199 |
2c1387cc558515919e2585b5708fd219 |
| |
| Alpha: |
ftp://updates.redhat.com/7.0/en/os/alpha/tar-1.13.25-4.7.1.alpha.rpm
Missing file |
c12063f58936ceb68848530b8e69d304 |
ftp://updates.redhat.com/7.0/en/os/alpha/unzip-5.50-2.alpha.rpm
Missing file |
25e5cb389451c393a58c8e2755180925 |
| |
| IA-32: |
ftp://updates.redhat.com/7.0/en/os/i386/tar-1.13.25-4.7.1.i386.rpm
Missing file |
fb5f89ea78abb60d50424dda0ac0db79 |
ftp://updates.redhat.com/7.0/en/os/i386/unzip-5.50-2.i386.rpm
Missing file |
877f4fda6198e604b539fb85664a3aad |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/SRPMS/tar-1.13.25-4.7.1.src.rpm
Missing file |
0b54c5bd9400cdedd26bdf64d9e69a80 |
unzip-5.50-2.src.rpm
File outdated by: RHSA-2003:199 |
2c1387cc558515919e2585b5708fd219 |
| |
| Alpha: |
ftp://updates.redhat.com/7.1/en/os/alpha/tar-1.13.25-4.7.1.alpha.rpm
Missing file |
c12063f58936ceb68848530b8e69d304 |
ftp://updates.redhat.com/7.1/en/os/alpha/unzip-5.50-2.alpha.rpm
Missing file |
25e5cb389451c393a58c8e2755180925 |
| |
| IA-32: |
ftp://updates.redhat.com/7.1/en/os/i386/tar-1.13.25-4.7.1.i386.rpm
Missing file |
fb5f89ea78abb60d50424dda0ac0db79 |
unzip-5.50-2.i386.rpm
File outdated by: RHSA-2003:199 |
877f4fda6198e604b539fb85664a3aad |
| |
| IA-64: |
ftp://updates.redhat.com/7.1/en/os/ia64/tar-1.13.25-4.7.1.ia64.rpm
Missing file |
a8aa3558565507d16f8cb91b6fed5d88 |
ftp://updates.redhat.com/7.1/en/os/ia64/unzip-5.50-2.ia64.rpm
Missing file |
f233de217386e5913b6460d22022dbb6 |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
ftp://updates.redhat.com/7.2/en/os/SRPMS/tar-1.13.25-4.7.1.src.rpm
Missing file |
0b54c5bd9400cdedd26bdf64d9e69a80 |
unzip-5.50-2.src.rpm
File outdated by: RHSA-2003:199 |
2c1387cc558515919e2585b5708fd219 |
| |
| IA-32: |
ftp://updates.redhat.com/7.2/en/os/i386/tar-1.13.25-4.7.1.i386.rpm
Missing file |
fb5f89ea78abb60d50424dda0ac0db79 |
unzip-5.50-2.i386.rpm
File outdated by: RHSA-2003:199 |
877f4fda6198e604b539fb85664a3aad |
| |
| IA-64: |
ftp://updates.redhat.com/7.2/en/os/ia64/tar-1.13.25-4.7.1.ia64.rpm
Missing file |
a8aa3558565507d16f8cb91b6fed5d88 |
unzip-5.50-2.ia64.rpm
File outdated by: RHSA-2003:199 |
f233de217386e5913b6460d22022dbb6 |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
ftp://updates.redhat.com/7.3/en/os/SRPMS/tar-1.13.25-4.7.1.src.rpm
Missing file |
0b54c5bd9400cdedd26bdf64d9e69a80 |
| |
| IA-32: |
ftp://updates.redhat.com/7.3/en/os/i386/tar-1.13.25-4.7.1.i386.rpm
Missing file |
fb5f89ea78abb60d50424dda0ac0db79 |
| |