PT-2005-1977 · Bzip2+1 · Bzip2+1

Imran Ghory

·

Publicado

2005-04-03

·

Atualizado

2018-10-19

·

CVE-2005-0953

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions bzip2 versions 1.0.2 and earlier
Description A race condition issue exists, allowing local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed. This occurs because the permissions of the file are changed by bzip2 after the decompression is complete.
Recommendations For bzip2 versions 1.0.2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0953
DSA-730-1
RHSA-2005:474
RHSA-2005_474

Produtos afetados

Red Hat
Bzip2