VDB

RHSA-2003%3A200

RHSA-2003%3A200 PUBLISHED

Updated unzip packages resolving a vulnerability allowing arbitrary files to be overwritten are now available. [Updated 15 August 2003] Ben Laurie found that the original patch to fix this issue missed a case where the path component included a quoted slash. These updated packages contain a new patch that corrects this issue.

Affected Products

VendorProductVersions
Red Hat Enterprise Linux WS version 2.1
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
Red Hat Enterprise Linux ES version 2.1
Red Hat Linux Advanced Workstation 2.1

Timeline

  • Jul 1, 2003 CVE Published
  • Nov 21, 2025 CVE Updated
  • Apr 7, 2026 Distribution Patch
  • Apr 7, 2026 Distribution Patch
  • Apr 7, 2026 Security Advisory
  • Aug 7, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›