CVE Vulnerabilities

CVE-2004-0970

Published: Feb 09, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.

Affected Software

NameVendorStart VersionEnd Version
GzipGnu1.2.4a (including)1.2.4a (including)
CscopeUbuntudapper*
CscopeUbuntudevel*
CscopeUbuntuedgy*
CscopeUbuntufeisty*

References