-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 14 Sep 2006 12:10:04 +0000 Source: gzip Binary: gzip Architecture: amd64 Version: 1.3.5-12ubuntu0.1 Distribution: dapper-security Urgency: low Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Martin Pitt Description: gzip - The GNU compression utility Changes: gzip (1.3.5-12ubuntu0.1) dapper-security; urgency=low . * SECURITY UPDATE: Arbitrary code execution or DoS with specially crafted gzipped/compress'ed files. Tavis Ormandy did a comprehensive security review, applied his patch to fix the following issues: * NULL Dereference [CVE-2006-4334]. * Buffer overflows in LZH uncompressor's make_table() [CVE-2006-4335, CVE-2006-4337]. * Buffer underflow in gzip unpacker's build_tree() [CVE-2006-4336]. * Infinite loop in LZH uncompressor [CVE-2006-4338]. Files: 5e9e2d325e742ce73c3c070e5d7856b3 76470 base required gzip_1.3.5-12ubuntu0.1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFFCUhH0N0xjzyQZEIRAuTJAJ9p661pS8F+ySQs22mP3lnFO05zzwCfdlTK tGXJyd4c9I3S2Jc0nj8dUH0= =gTPM -----END PGP SIGNATURE-----