CVE Vulnerabilities

CVE-2005-0758

Published: May 13, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

Affected Software

NameVendorStart VersionEnd Version
GzipGnu*1.3.5 (excluding)
Red Hat Enterprise Linux 3RedHatgzip-0:1.3.3-12.rhel3*
Red Hat Enterprise Linux 3RedHatbzip2-0:1.0.2-11.EL3.4*
Red Hat Enterprise Linux 4RedHatgzip-0:1.3.3-15.rhel4*
Red Hat Enterprise Linux 4RedHatbzip2-0:1.0.2-13.EL4.3*
Bzip2Ubuntudapper*
Bzip2Ubuntudevel*
Bzip2Ubuntuedgy*
Bzip2Ubuntufeisty*
GzipUbuntudapper*
GzipUbuntudevel*
GzipUbuntuedgy*
GzipUbuntufeisty*

References