PT-2005-1650 · Info Zip · Unzip

Albert Puigsech Galicia

·

Published

2005-03-01

·

Updated

2016-10-18

·

CVE-2005-0602

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Unzip versions 5.51 and earlier
Description The issue is related to the extraction of setuid or setgid files, where the software does not properly warn the user. This may allow local users to gain privileges.
Recommendations For Unzip versions 5.51 and earlier, update to a version that properly handles the extraction of setuid or setgid files to prevent potential privilege escalation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0602

Affected Products

Unzip