zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gzip | Gnu | * | 1.3.5 (excluding) |
Red Hat Enterprise Linux 3 | RedHat | gzip-0:1.3.3-12.rhel3 | * |
Red Hat Enterprise Linux 3 | RedHat | bzip2-0:1.0.2-11.EL3.4 | * |
Red Hat Enterprise Linux 4 | RedHat | gzip-0:1.3.3-15.rhel4 | * |
Red Hat Enterprise Linux 4 | RedHat | bzip2-0:1.0.2-13.EL4.3 | * |
Bzip2 | Ubuntu | dapper | * |
Bzip2 | Ubuntu | devel | * |
Bzip2 | Ubuntu | edgy | * |
Bzip2 | Ubuntu | feisty | * |
Gzip | Ubuntu | dapper | * |
Gzip | Ubuntu | devel | * |
Gzip | Ubuntu | edgy | * |
Gzip | Ubuntu | feisty | * |