CVE Vulnerabilities

CVE-2004-1349

Improper Privilege Management

Published: Oct 04, 2004 | Modified: Mar 24, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Gzip Gnu * 1.3 (excluding)
Solaris Oracle 8 (including) 8 (including)

Potential Mitigations

References