Scientific Linux Security Update : unzip on SL4.x i386/x86_64

This script is Copyright (C) 2012 Tenable Network Security, Inc.

Synopsis :

The remote Scientific Linux host is missing a security update.

Description :

A race condition was found in Unzip. Local users could use this flaw
to modify permissions of arbitrary files via a hard link attack on a
file while it was being decompressed (CVE-2005-2475)

A buffer overflow was found in Unzip command line argument handling.
If a user could be tricked into running Unzip with a specially crafted
long file name, an attacker could execute arbitrary code with that
user's privileges. (CVE-2005-4667)

See also :

Solution :

Update the affected unzip package.

Risk factor :

Low / CVSS Base Score : 3.7

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 60171 ()

Bugtraq ID:

CVE ID: CVE-2005-2475