CVE Vulnerabilities

CVE-2005-0988

Published: May 02, 2005 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

Affected Software

Name Vendor Start Version End Version
Gzip Gnu 1.2.4 (including) 1.2.4 (including)
Gzip Gnu 1.2.4a (including) 1.2.4a (including)
Gzip Gnu 1.3.3 (including) 1.3.3 (including)
Gzip Ubuntu dapper *
Gzip Ubuntu devel *
Gzip Ubuntu edgy *
Gzip Ubuntu feisty *
Red Hat Enterprise Linux 3 RedHat gzip-0:1.3.3-12.rhel3 *
Red Hat Enterprise Linux 4 RedHat gzip-0:1.3.3-15.rhel4 *

References