5
CVSSv2

CVE-2005-1228

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in gunzip -N in gzip 1.2.4 up to and including 1.3.5 allows remote malicious users to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gzip 1.2.4

gnu gzip 1.3.3

Vendor Advisories

Synopsis gzip security update Type/Severity Security Advisory: Low Topic An updated gzip package is now availableThis update has been rated as having low security impact by the Red HatSecurity Response Team Description The gzip package contains the GNU gzip data compression programA bug ...
Imran Ghory discovered a race condition in the file permission restore code of gzip and gunzip While a user was compressing or decompressing a file, a local attacker with write permissions in the directory of that file could replace the target file with a hard link This would cause gzip to restore the file permissions to the hard link target ins ...