DSA-100-1 gzip -- Potential buffer overflow

Date Reported:
13 Jan 2002
In Mitre's CVE dictionary: CVE-2001-1228.
GOBBLES found a buffer overflow in gzip that occurs when compressing files with really long filenames. Even though GOBBLES claims to have developed an exploit to take advantage of this bug, it has been said by others that this problem is not likely to be exploitable as other security incidents.

Additionally, the Debian version of gzip from the stable release does not segfault, and hence does not directly inherit this problem. However, better be safe than sorry, so we have prepared an update for you.

Please make sure you are running an up-to-date version from stable/unstable/testing with at least version 1.2.4-33.

Fixed in:

Debian GNU/Linux 2.2 (potato)

