CVE Vulnerabilities

CVE-2005-0953

Published: May 02, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

Affected Software

NameVendorStart VersionEnd Version
Bzip2Bzip0.9 (including)0.9 (including)
Bzip2Bzip0.9.5_a (including)0.9.5_a (including)
Bzip2Bzip0.9.5_b (including)0.9.5_b (including)
Bzip2Bzip0.9.5_c (including)0.9.5_c (including)
Bzip2Bzip0.9.5_d (including)0.9.5_d (including)
Bzip2Bzip0.9_a (including)0.9_a (including)
Bzip2Bzip0.9_b (including)0.9_b (including)
Bzip2Bzip0.9_c (including)0.9_c (including)
Bzip2Bzip1.0 (including)1.0 (including)
Bzip2Bzip1.0.1 (including)1.0.1 (including)
Bzip2Bzip1.0.2 (including)1.0.2 (including)
Red Hat Enterprise Linux 3RedHatbzip2-0:1.0.2-11.EL3.4*
Red Hat Enterprise Linux 4RedHatbzip2-0:1.0.2-13.EL4.3*
Bzip2Ubuntudapper*
Bzip2Ubuntudevel*
Bzip2Ubuntuedgy*
Bzip2Ubuntufeisty*

References