2.1
CVSSv2

CVE-2003-0367

Published: 02/07/2003 Updated: 23/05/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gzip

debian debian linux 2.2

debian debian linux 3.0

Vendor Advisories

Paul Szabo discovered that znew, a script included in the gzip package, creates its temporary files without taking precautions to avoid a symlink attack (CAN-2003-0367) The gzexe script has a similar vulnerability which was patched in an earlier release but inadvertently reverted For the stable distribution (woody) both problems have been fixed i ...