CVE Vulnerabilities

CVE-2005-0988

Published: May 02, 2005 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

Affected Software

Name Vendor Start Version End Version
Gzip Gnu 1.2.4 (including) 1.2.4 (including)
Gzip Gnu 1.2.4a (including) 1.2.4a (including)
Gzip Gnu 1.3.3 (including) 1.3.3 (including)
Red Hat Enterprise Linux 3 RedHat gzip-0:1.3.3-12.rhel3 *
Red Hat Enterprise Linux 4 RedHat gzip-0:1.3.3-15.rhel4 *
Gzip Ubuntu dapper *
Gzip Ubuntu devel *
Gzip Ubuntu edgy *
Gzip Ubuntu feisty *

References