1.2
CVSSv2

CVE-2002-0760

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Race condition in bzip2 prior to 1.0.2 in FreeBSD 4.5 and previous versions, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions before setting the permissions to what is specified in the bzip2 archive, which could allow local users to read the files as they are being decompressed.

Vulnerable Product Search on Vulmon Subscribe to Product

bzip bzip2 0.9.0

bzip bzip2 0.9.0a

bzip bzip2 0.9.0b

bzip bzip2 0.9.5a

bzip bzip2 0.9.5c

bzip bzip2 0.9.5d

bzip bzip2 1.0

bzip bzip2 1.0.1

bzip bzip2 0.9.0c

bzip bzip2 0.9.5b