zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gzip | Gnu | * | 1.3.5 (excluding) |
| Red Hat Enterprise Linux 3 | RedHat | gzip-0:1.3.3-12.rhel3 | * |
| Red Hat Enterprise Linux 3 | RedHat | bzip2-0:1.0.2-11.EL3.4 | * |
| Red Hat Enterprise Linux 4 | RedHat | gzip-0:1.3.3-15.rhel4 | * |
| Red Hat Enterprise Linux 4 | RedHat | bzip2-0:1.0.2-13.EL4.3 | * |
| Bzip2 | Ubuntu | dapper | * |
| Bzip2 | Ubuntu | devel | * |
| Bzip2 | Ubuntu | edgy | * |
| Bzip2 | Ubuntu | feisty | * |
| Gzip | Ubuntu | dapper | * |
| Gzip | Ubuntu | devel | * |
| Gzip | Ubuntu | edgy | * |
| Gzip | Ubuntu | feisty | * |