PT-2014-2157 · Bzip2 · Bzip2

Vladz

·

Publicado

2014-04-16

·

Atualizado

2014-04-17

·

CVE-2011-4089

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions bzip2 versions 1.0.5 and earlier
Description The issue arises from the bzexe command in bzip2, which generates compressed executables that do not properly handle temporary files during extraction. This allows local users to execute arbitrary code by precreating a temporary directory.
Recommendations For bzip2 versions 1.0.5 and earlier, consider updating to a version later than 1.0.5 to resolve the issue. As a temporary workaround, restrict access to the bzexe command to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4089

Produtos afetados

Bzip2