6.2
CVSSv2

CVE-2005-0602

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unzip 5.51 and previous versions does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

info-zip unzip

info-zip unzip 5.50

Vendor Advisories

If a ZIP archive contains binaries with the setuid and/or setgid bit set, unzip preserved those bits when extracting the archive This could be exploited by tricking the administrator into unzipping an archive with a setuid-root binary into a directory the attacker can access This allowed the attacker to execute arbitrary commands with root privi ...