RHSA-2022:1592: Important: gzip security update
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.<br>Security Fix(es):<br><li> gzip: arbitrary-file-write vulnerability (CVE-2022-1271)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1592?
The severity of RHSA-2022:1592 is classified as high due to its potential for arbitrary file modification.
How do I fix RHSA-2022:1592?
To fix RHSA-2022:1592, update the gzip package to version 1.9-10.el8_1 or later.
Which systems are affected by RHSA-2022:1592?
RHSA-2022:1592 affects systems running vulnerable versions of the gzip package including Red Hat Enterprise Linux 8.
What does the vulnerability in RHSA-2022:1592 allow an attacker to do?
The vulnerability in RHSA-2022:1592 allows an attacker to modify arbitrary files on the system.
Is there a workaround for RHSA-2022:1592?
There are no specified workarounds for RHSA-2022:1592, so patching is the recommended action.