Trustix developers discovered insecure temporary file creation in supplemental scripts in the gzip package which may allow local users to overwrite files via a symlink attack.
For the stable distribution (woody) these problems have been fixed in version 1.3.2-3woody3.
The unstable distribution (sid) is not affected by these problems.
We recommend that you upgrade your gzip package.
MD5 checksums of the listed files are available in the original advisory.