PT-2005-1650 · Info Zip · Unzip
Albert Puigsech Galicia
·
Published
2005-03-01
·
Updated
2016-10-18
·
CVE-2005-0602
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Unzip versions 5.51 and earlier
Description
The issue is related to the extraction of setuid or setgid files, where the software does not properly warn the user. This may allow local users to gain privileges.
Recommendations
For Unzip versions 5.51 and earlier, update to a version that properly handles the extraction of setuid or setgid files to prevent potential privilege escalation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unzip