CVE Vulnerabilities

CVE-2002-0759

Published: Aug 12, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the user if an existing file would be overwritten, which could allow attackers to overwrite files via a bzip2 archive.

Affected Software

Name Vendor Start Version End Version
Bzip2 Bzip 0.9.0 (including) 0.9.0 (including)
Bzip2 Bzip 0.9.0a (including) 0.9.0a (including)
Bzip2 Bzip 0.9.0b (including) 0.9.0b (including)
Bzip2 Bzip 0.9.0c (including) 0.9.0c (including)
Bzip2 Bzip 0.9.5a (including) 0.9.5a (including)
Bzip2 Bzip 0.9.5b (including) 0.9.5b (including)
Bzip2 Bzip 0.9.5c (including) 0.9.5c (including)
Bzip2 Bzip 0.9.5d (including) 0.9.5d (including)
Bzip2 Bzip 1.0 (including) 1.0 (including)
Bzip2 Bzip 1.0.1 (including) 1.0.1 (including)

References