CVE Vulnerabilities

CVE-2005-1111

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: May 02, 2005 | Modified: Jan 26, 2024
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

Affected Software

Name Vendor Start Version End Version
Cpio Gnu * 2.6 (including)
Red Hat Enterprise Linux 3 RedHat cpio-0:2.5-4.RHEL3 *
Red Hat Enterprise Linux 4 RedHat cpio-0:2.5-8.RHEL4 *
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Cpio Ubuntu dapper *
Cpio Ubuntu devel *
Cpio Ubuntu edgy *
Cpio Ubuntu feisty *

Potential Mitigations

References