PT-2014-2157 · Bzip2 · Bzip2

Vladz

·

Published

2014-04-16

·

Updated

2014-04-17

·

CVE-2011-4089

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions bzip2 versions 1.0.5 and earlier
Description The issue arises from the bzexe command in bzip2, which generates compressed executables that do not properly handle temporary files during extraction. This allows local users to execute arbitrary code by precreating a temporary directory.
Recommendations For bzip2 versions 1.0.5 and earlier, consider updating to a version later than 1.0.5 to resolve the issue. As a temporary workaround, restrict access to the bzexe command to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4089

Affected Products

Bzip2