4.4
CVSSv2

CVE-2013-0296

Published: 27/04/2014 Updated: 28/04/2014
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Race condition in pigz prior to 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zlib pigz

Vendor Advisories

Debian Bug report logs - #775306 pxz: CVE-2015-1200: race condition in setting permissions Package: pxz; Maintainer for pxz is Holger Levsen <holger@debianorg>; Source for pxz is src:pxz (PTS, buildd, popcon) Reported by: Alexander Cherepanov <cherepan@mccmeru> Date: Tue, 13 Jan 2015 21:45:01 UTC Severity: importa ...
Debian Bug report logs - #700608 pigz creates temp files with too wide permissions (CVE-2013-0296) Package: pigz; Maintainer for pigz is Eduard Bloch <blade@debianorg>; Source for pigz is src:pigz (PTS, buildd, popcon) Reported by: Michael Tokarev <mjt@tlsmskru> Date: Fri, 15 Feb 2013 08:33:01 UTC Severity: serio ...