Security Advisory zip security update

Advisory: RHSA-2004:634-08
Type: Security Advisory
Severity: Low
Issued on: 2004-12-16
Last updated on: 2004-12-16
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-1010

Details

An updated zip package that fixes a buffer overflow vulnerability is now
available.

The zip program is an archiving utility which can create ZIP-compatible
archives.

A buffer overflow bug has been discovered in zip when handling long file
names. An attacker could create a specially crafted path which could
cause zip to crash or execute arbitrary instructions. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-1010 to this issue.

Users of zip should upgrade to this updated package, which contains
backported patches and is not vulnerable to this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
zip-2.3-16.1.src.rpm     aa360ac25cf50772fd010cf2d1d91db7
 
IA-32:
zip-2.3-16.1.i386.rpm     41fec60bfbbca5266e4bbff55f42031a
 
x86_64:
zip-2.3-16.1.x86_64.rpm     1ed34c119e86a0c739c1c5bb706ffb69
 
Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
zip-2.3-10.1.src.rpm     b062c345c3d6c56ed1c042145643c8c8
 
IA-32:
zip-2.3-10.1.i386.rpm     a06a150a5652173a8309cca26cc3c70f
 
IA-64:
zip-2.3-10.1.ia64.rpm     6cab305bdaca789e53e760184050fab9
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
zip-2.3-16.1.src.rpm     aa360ac25cf50772fd010cf2d1d91db7
 
IA-32:
zip-2.3-16.1.i386.rpm     41fec60bfbbca5266e4bbff55f42031a
 
IA-64:
zip-2.3-16.1.ia64.rpm     0b8464b40ec9d081dd36ab9d699a4c1c
 
PPC:
zip-2.3-16.1.ppc.rpm     787ad3673b90f4fcb0d47c815ca984f6
 
s390:
zip-2.3-16.1.s390.rpm     97c709a606b3cec173833833b24c704b
 
s390x:
zip-2.3-16.1.s390x.rpm     4d1f10e6b1e4247cb037eb42c8fcc796
 
x86_64:
zip-2.3-16.1.x86_64.rpm     1ed34c119e86a0c739c1c5bb706ffb69
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
zip-2.3-10.1.src.rpm     b062c345c3d6c56ed1c042145643c8c8
 
IA-32:
zip-2.3-10.1.i386.rpm     a06a150a5652173a8309cca26cc3c70f
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
zip-2.3-16.1.src.rpm     aa360ac25cf50772fd010cf2d1d91db7
 
IA-32:
zip-2.3-16.1.i386.rpm     41fec60bfbbca5266e4bbff55f42031a
 
IA-64:
zip-2.3-16.1.ia64.rpm     0b8464b40ec9d081dd36ab9d699a4c1c
 
x86_64:
zip-2.3-16.1.x86_64.rpm     1ed34c119e86a0c739c1c5bb706ffb69
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
zip-2.3-10.1.src.rpm     b062c345c3d6c56ed1c042145643c8c8
 
IA-32:
zip-2.3-10.1.i386.rpm     a06a150a5652173a8309cca26cc3c70f
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
zip-2.3-16.1.src.rpm     aa360ac25cf50772fd010cf2d1d91db7
 
IA-32:
zip-2.3-16.1.i386.rpm     41fec60bfbbca5266e4bbff55f42031a
 
IA-64:
zip-2.3-16.1.ia64.rpm     0b8464b40ec9d081dd36ab9d699a4c1c
 
x86_64:
zip-2.3-16.1.x86_64.rpm     1ed34c119e86a0c739c1c5bb706ffb69
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
zip-2.3-10.1.src.rpm     b062c345c3d6c56ed1c042145643c8c8
 
IA-64:
zip-2.3-10.1.ia64.rpm     6cab305bdaca789e53e760184050fab9
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

138228 - CAN-2004-1010 buffer overflow when creating archive containing very long filenames.


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/