unzip vulnerability

Related Vulnerabilities: CVE-2005-2475  

Imran Ghory found a race condition in the handling of output files. While a file was unpacked by unzip, a local attacker with write permissions to the target directory could exploit this to change the permissions of arbitrary files of the unzip user.

The problem can be corrected by updating your system to the following package versions:

30 September 2005

unzip vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.04
  • Ubuntu 4.10

Software Description

Details

Imran Ghory found a race condition in the handling of output files. While a file was unpacked by unzip, a local attacker with write permissions to the target directory could exploit this to change the permissions of arbitrary files of the unzip user.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.04
unzip
Ubuntu 4.10
unzip

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References