* Technical Description *
Redhat has released a security patch to correct three vulnerabilities identified in gzip. These flaws may be exploited by attackers to execute arbitrary commands, change the permissions of arbitrary files, and place files to aribitrary locations. For additional information, see : FrSIRT/ADV-2005-0460
* Affected Products *
Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
* Solution *
Use Red Hat Network to download and update your packages :
http://rhn.redhat.com/ * References *
http://www.frsirt.com/english/advisories/2005/0754http://rhn.redhat.com/errata/RHSA-2005-357.html