CVE Vulnerabilities

CVE-2022-1271

Incorrect Behavior Order: Early Validation

Published: Aug 31, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

An arbitrary file write vulnerability was found in GNU gzips zgrep utility. When zgrep is applied on the attackers chosen file name (for example, a crafted file name), this can overwrite an attackers content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

Weakness

The product validates input before applying protection mechanisms that modify the input, which could allow an attacker to bypass the validation via dangerous inputs that only arise after the modification.

Affected Software

Name Vendor Start Version End Version
Gzip Gnu * 1.12 (excluding)
Red Hat Enterprise Linux 7 RedHat gzip-0:1.5-11.el7_9 *
Red Hat Enterprise Linux 7 RedHat xz-0:5.2.2-2.el7_9 *
Red Hat Enterprise Linux 8 RedHat gzip-0:1.9-13.el8_5 *
Red Hat Enterprise Linux 8 RedHat xz-0:5.2.4-4.el8_6 *
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions RedHat gzip-0:1.9-10.el8_1 *
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions RedHat xz-0:5.2.4-4.el8_1 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat gzip-0:1.9-10.el8_2 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat xz-0:5.2.4-4.el8_2 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat gzip-0:1.9-13.el8_4 *
Red Hat Enterprise Linux 8.4 Extended Update Support RedHat xz-0:5.2.4-4.el8_4 *
Red Hat Enterprise Linux 9 RedHat xz-0:5.2.5-8.el9_0 *
Red Hat Enterprise Linux 9 RedHat gzip-0:1.10-9.el9_0 *
Red Hat Enterprise Linux 9 RedHat xz-0:5.2.5-8.el9_0 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat redhat-virtualization-host-0:4.3.23-20220622.0.el7_9 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 RedHat redhat-virtualization-host-0:4.5.0-202205291010_8.6 *
Gzip Ubuntu bionic *
Gzip Ubuntu devel *
Gzip Ubuntu esm-infra/xenial *
Gzip Ubuntu focal *
Gzip Ubuntu impish *
Gzip Ubuntu jammy *
Gzip Ubuntu trusty *
Gzip Ubuntu trusty/esm *
Gzip Ubuntu xenial *
Xz-utils Ubuntu bionic *
Xz-utils Ubuntu devel *
Xz-utils Ubuntu esm-infra/xenial *
Xz-utils Ubuntu focal *
Xz-utils Ubuntu impish *
Xz-utils Ubuntu jammy *
Xz-utils Ubuntu trusty/esm *

Potential Mitigations

References