CVE Vulnerabilities

CVE-2002-0761

Published: Aug 12, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Bzip2 Bzip 0.9.0 (including) 0.9.0 (including)
Bzip2 Bzip 0.9.0a (including) 0.9.0a (including)
Bzip2 Bzip 0.9.0b (including) 0.9.0b (including)
Bzip2 Bzip 0.9.0c (including) 0.9.0c (including)
Bzip2 Bzip 0.9.5a (including) 0.9.5a (including)
Bzip2 Bzip 0.9.5b (including) 0.9.5b (including)
Bzip2 Bzip 0.9.5c (including) 0.9.5c (including)
Bzip2 Bzip 0.9.5d (including) 0.9.5d (including)
Bzip2 Bzip 1.0 (including) 1.0 (including)
Bzip2 Bzip 1.0.1 (including) 1.0.1 (including)

References