CVE-2005-0988

Severity

37%

Complexity

19%

Confidentiality

106%

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

CVSS 2.0 Base Score 3.7. CVSS Attack Vector: local. CVSS Attack Complexity: high. CVSS Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:P).

Overview

First reported 19 years ago

2005-05-02 04:00:00

Last updated 7 years ago

2017-10-11 01:30:00

Affected Software

GNU Gzip 1.2.4

1.2.4

GNU Gzip 1.2.4a

1.2.4a

GNU Gzip 1.3.3

1.3.3

FreeBSD 4.0

4.0

FreeBSD 4.1

4.1

FreeBSD 4.1.1

4.1.1

FreeBSD 4.2

4.2

FreeBSD 4.3

4.3

FreeBSD 4.4

4.4

FreeBSD 4.5

4.5

FreeBSD 4.6

4.6

FreeBSD 4.6.2

4.6.2

FreeBSD 4.7

4.7

FreeBSD 4.8

4.8

FreeBSD 4.9

4.9

FreeBSD 4.10

4.10

FreeBSD 5.0

5.0

FreeBSD 5.1

5.1

FreeBSD 5.2

5.2

FreeBSD 5.3

5.3

Gentoo Linux

Red Hat Desktop 3.0

3.0

Red Hat Desktop 4.0

4.0

Trustix Secure Linux 2.0

2.0

Trustix Secure Linux 2.1

2.1

Trustix Secure Linux 2.2

2.2

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.