Bug 207643 - CVE-2006-4334 Multiple vunabilities in gzip (CVE-2006-4335, CVE-2006-4336, CVE-2006-4337, CVE CVE-2006-4338)
Summary: CVE-2006-4334 Multiple vunabilities in gzip (CVE-2006-4335, CVE-2006-4336, CV...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: gzip
Version: 5
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
Assignee: Ivana Varekova
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On: 204676
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-09-22 06:37 UTC by Heiko Adams
Modified: 2007-11-30 22:11 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-10-10 07:30:15 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Heiko Adams 2006-09-22 06:37:32 UTC
Description of problem:
Google Security Team has dicovered multiple vunabilities in gzip 1.3.5. These
vunabilities are recorded as CVE-2006-4334, CVE-2006-4335, CVE-2006-4336,
CVE-2006-4337, CVE-2006-4338.

Version-Release number of selected component (if applicable):
1.3.5  

Additional info:
These vunabilities are already fixed for Red Hats commercial linux
distributions. Where is the updated package for fedora core??

Comment 1 Ivana Varekova 2006-09-22 15:51:36 UTC
fixed in gzip-1.3.5-8.

Comment 2 Michal Jaegermann 2006-09-26 19:34:57 UTC
> fixed in gzip-1.3.5-8

gzip-1.3.5-8 is from rawhide and this update indeed showed up there
some time ago.  But for FC5 gzip-1.3.5-7.1.fc5 sits for a number
of days already in "testing" and released packages do not seem to be
forthcoming.  See bug 204676 for a description of attacks.

Comment 3 Josh Bressers 2006-09-30 21:23:10 UTC
Ivana, it seems you forgot to push this one live, can you take care of it ASAP?

Comment 4 Ivana Varekova 2006-10-10 07:30:15 UTC
The update gzip-1.3.5-7.1.fc5 is pushed as final now.

Comment 5 Peter E. Popovich 2006-10-12 20:22:57 UTC
gzip 1.3.5-7.1 was pushed 2006-10-02
gzip 1.3.5-7 was pushed 2006-10-10

Note that the 10/02 version is later than the 10/10 version.

Does 1.3.5-7.1 have the relevant fix?

Or does someone need to release a 1.3.5-7.2?

Comment 6 MATSUU Takuto 2006-10-13 02:51:36 UTC
gzip-1.3.3 also has these vulnerabilities. FC3 is affected. see RHSA-2006-0667


Comment 7 Kasper Dupont 2006-10-13 05:17:40 UTC
I noticed that 1.3.5-7.fc5 and 1.3.5-7.1.fc5 where made available for download
in the opposite order of being build. So which one should I be using?
Intuitively the extra .1 sounds like a higher version number. But
lexicographically .1.fc5 is before .fc5, and neither have an epoch. Maybe I
misunderstood the algorithm for comparing version numbers, is it documented
anywhere?

Comment 8 Ivana Varekova 2006-10-13 14:31:08 UTC
The problem with update is fixed by 1.3.5-8.fc5

Comment 9 Kasper Dupont 2006-10-15 00:03:11 UTC
I don't see any gzip-1.3.5-8.fc5


Note You need to log in before you can comment on or make changes to this bug.