<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="cf2b0afd8f6b10f16eb564f537758acb"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1838">
  <id>dbg111-gzip</id>
  <title>gzip security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1264001139"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=570331" id="570331" title="bug number 570331" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624" id="CVE-2009-2624" title="CVE-2009-2624" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0001" id="CVE-2010-0001" title="CVE-2010-0001" type="cve"/>
  </references>
  <description>Specially crafted gzip archives could lead to gzip
allocating a too small huffman table. Attackers could
exploit that to crash gzip (CVE-2009-2624).

Specially crafted gzip archives could trigger integer
overflows. Attackers could exploit that to crash gzip or
potentially execute arbitrary code (CVE-2010-0001). Only
64bit architectures are affected by this flaw.
</description>
  <pkglist>
    <collection>
        <package name="gzip-debuginfo" arch="i586" version="1.3.12" release="68.39.1">
          <filename>gzip-debuginfo-1.3.12-68.39.1.i586.rpm</filename>
        </package>
        <package name="gzip-debuginfo" arch="ppc" version="1.3.12" release="68.39.1">
          <filename>gzip-debuginfo-1.3.12-68.39.1.ppc.rpm</filename>
        </package>
        <package name="gzip-debuginfo" arch="x86_64" version="1.3.12" release="68.39.1">
          <filename>gzip-debuginfo-1.3.12-68.39.1.x86_64.rpm</filename>
        </package>
        <package name="gzip-debugsource" arch="i586" version="1.3.12" release="68.39.1">
          <filename>gzip-debugsource-1.3.12-68.39.1.i586.rpm</filename>
        </package>
        <package name="gzip-debugsource" arch="ppc" version="1.3.12" release="68.39.1">
          <filename>gzip-debugsource-1.3.12-68.39.1.ppc.rpm</filename>
        </package>
        <package name="gzip-debugsource" arch="x86_64" version="1.3.12" release="68.39.1">
          <filename>gzip-debugsource-1.3.12-68.39.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
