Sunday, November 14, 2010

bzip2: Important Security Update

Users of bzip2 please be advised of an Important security update fix arbitrary code execution vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
RHSA-2010:0858-03: [RHSA-2010:0858-03] Important: bzip2 security update
Product: Red Hat Enterprise Linux
Description:



bzip2 is a freely available, high-quality data compressor. It provides both

standalone compression and decompression utilities, as well as a shared

library for use with other programs.



An integer overflow flaw was discovered in the bzip2 decompression routine.

This issue could, when decompressing malformed archives, cause bzip2, or an

application linked against the libbz2 library, to crash or, potentially,

execute arbitrary code. (CVE-2010-0405)
Users of bzip2 should upgrade to these updated packages, which contain a

backported patch to resolve this issue. All running applications using the

libbz2 library must be restarted for the update to take effect.


Read more at www.criticalwatch.com
 

No comments:

Post a Comment