RHEL 2.1 : unzip (RHSA-2003:200)

Low Nessus Plugin ID 12403


The remote Red Hat host is missing a security update.


Updated unzip packages resolving a vulnerability allowing arbitrary files to be overwritten are now available.

[Updated 15 August 2003] Ben Laurie found that the original patch to fix this issue missed a case where the path component included a quoted slash. These updated packages contain a new patch that corrects this issue.

The unzip utility is used for manipulating archives, which are multiple files stored inside of a single file.

A vulnerabilitiy in unzip version 5.50 and earlier allows attackers to overwrite arbitrary files during archive extraction by placing invalid (non-printable) characters between two '.' characters. These non-printable characters are filtered, resulting in a '..' sequence.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0282 to this issue.

This erratum includes a patch ensuring that non-printable characters do not make it possible for a malicious .zip file to write to parent directories unless the '-:' command line parameter is specified.

Users of unzip are advised to upgrade to these updated packages, which are not vulnerable to this issue.


Update the affected unzip package.

See Also




Plugin Details

Severity: Low

ID: 12403

File Name: redhat-RHSA-2003-200.nasl

Version: $Revision: 1.21 $

Type: local

Agent: unix

Published: 2004/07/06

Modified: 2016/12/28

Dependencies: 12634

Risk Information

Risk Factor: Low


Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:unzip, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 2003/08/15

Reference Information

CVE: CVE-2003-0282

RHSA: 2003:200