This script is Copyright (C) 2004-2016 Tenable Network Security, Inc.
The remote Red Hat host is missing a security update.
An updated zip package that fixes a buffer overflow vulnerability is
The zip program is an archiving utility which can create
A buffer overflow bug has been discovered in zip when handling long
file names. An attacker could create a specially crafted path which
could cause zip to crash or execute arbitrary instructions. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
name CVE-2004-1010 to this issue.
Users of zip should upgrade to this updated package, which contains
backported patches and is not vulnerable to this issue.
See also :
Update the affected zip package.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.3
Public Exploit Available : true
Family: Red Hat Local Security Checks
Nessus Plugin ID: 15990 ()
CVE ID: CVE-2004-1010
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.