5
CVSSv2

CVE-2002-0759

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

bzip2 prior to 1.0.2 in FreeBSD 4.5 and previous versions, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the user if an existing file would be overwritten, which could allow malicious users to overwrite files via a bzip2 archive.

Vulnerable Product Search on Vulmon Subscribe to Product

bzip bzip2 0.9.5c

bzip bzip2 1.0

bzip bzip2 0.9.0a

bzip bzip2 0.9.0b

bzip bzip2 0.9.0c

bzip bzip2 0.9.5a

bzip bzip2 0.9.5b

bzip bzip2 0.9.0

bzip bzip2 0.9.5d

bzip bzip2 1.0.1