The release of the gzip 1.12 data compression utility suite has taken place. The new version addresses a vulnerability in the zgrep utility that allows overwriting arbitrary files in the system when processing a specially crafted filename containing two or more newline characters, depending on current permissions. This issue has been present since version 1.3.10, released in 2007.
Other changes include the discontinuation of zless installation on systems without the less utility, as well as ensuring that the output from the 'gzip -l' command correctly shows information about files larger than 4 GB (the information about the size of the unpacked data is now determined by actual unpacking with a real size count instead of a fixed 32-bit field from the header).
Source: opennet.ru
