RHSA-2022:2191: Important: gzip security update
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.Security Fix(es): gzip: arbitrary-file-write vulnerability (CVE-2022-1271) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:2191?
The severity of RHSA-2022:2191 is classified as important.
How do I fix RHSA-2022:2191?
To fix RHSA-2022:2191, update the gzip package to version 1.5-11.el7_9 or later.
Which versions of gzip are affected by RHSA-2022:2191?
All versions of gzip prior to 1.5-11.el7_9 are affected by RHSA-2022:2191.
What is the impact of RHSA-2022:2191?
RHSA-2022:2191 can lead to arbitrary file access due to vulnerabilities in the gzip utility.
Is RHSA-2022:2191 relevant for gzip-debuginfo packages?
Yes, RHSA-2022:2191 is also relevant for gzip-debuginfo packages associated with the gzip version mentioned.