1.2
CVSSv2

CVE-2005-2475

Published: 05/08/2005 Updated: 11/10/2017
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

info-zip unzip 5.52

Vendor Advisories

Imran Ghory found a race condition in the handling of output files While a file was unpacked by unzip, a local attacker with write permissions to the target directory could exploit this to change the permissions of arbitrary files of the unzip user ...
The unzip update in DSA 903 contained a regression so that symbolic links that are resolved later in a zip archive aren't supported anymore  This update corrects this behaviour  For completeness, below please find the original advisory text: Imran Ghory discovered a race condition in the permissions setting code in unzip When decompressing a ...