CVE Vulnerabilities

CVE-2002-0759

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the user if an existing file would be overwritten, which could allow attackers to overwrite files via a bzip2 archive.

Affected Software

NameVendorStart VersionEnd Version
Bzip2Bzip0.9.0 (including)0.9.0 (including)
Bzip2Bzip0.9.0a (including)0.9.0a (including)
Bzip2Bzip0.9.0b (including)0.9.0b (including)
Bzip2Bzip0.9.0c (including)0.9.0c (including)
Bzip2Bzip0.9.5a (including)0.9.5a (including)
Bzip2Bzip0.9.5b (including)0.9.5b (including)
Bzip2Bzip0.9.5c (including)0.9.5c (including)
Bzip2Bzip0.9.5d (including)0.9.5d (including)
Bzip2Bzip1.0 (including)1.0 (including)
Bzip2Bzip1.0.1 (including)1.0.1 (including)

References