2.1
CVSSv2

CVE-2015-1200

Published: 23/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pxz project pxz 4.999.99

Vendor Advisories

Debian Bug report logs - #775306 pxz: CVE-2015-1200: race condition in setting permissions Package: pxz; Maintainer for pxz is Holger Levsen <holger@debianorg>; Source for pxz is src:pxz (PTS, buildd, popcon) Reported by: Alexander Cherepanov <cherepan@mccmeru> Date: Tue, 13 Jan 2015 21:45:01 UTC Severity: importa ...