PT-2005-1977 · Bzip2+1 · Bzip2+1

Imran Ghory

·

Published

2005-04-03

·

Updated

2018-10-19

·

CVE-2005-0953

CVSS v2.0

3.7

Low

VectorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions bzip2 versions 1.0.2 and earlier
Description A race condition issue exists, allowing local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed. This occurs because the permissions of the file are changed by bzip2 after the decompression is complete.
Recommendations For bzip2 versions 1.0.2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0953
DSA-730-1
RHSA-2005:474
RHSA-2005_474

Affected Products

Red Hat
Bzip2