Vulnerability CVE-2005-2475


Published: 2005-08-05   Modified: 2012-02-12

Description:
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
OpenServer : UnZip File Permissions Change Vulnerability
SCO Security Adv...
29.09.2005

CVSS2 => (AV:L/AC:H/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
1.2/10
2.9/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Info-zip -> Unzip 

 References:
http://www.info-zip.org/FAQ.html
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9975
http://www.ubuntu.com/usn/usn-191-1
http://www.trustix.org/errata/2005/0053/
http://www.securityfocus.com/bid/14450
http://www.redhat.com/support/errata/RHSA-2007-0203.html
http://www.osvdb.org/18530
http://www.mandriva.com/security/advisories?name=MDKSA-2005:197
http://www.debian.org/security/2005/dsa-903
http://securityreason.com/securityalert/32
http://secunia.com/advisories/25098
http://secunia.com/advisories/17653
http://secunia.com/advisories/17342
http://secunia.com/advisories/17045
http://secunia.com/advisories/17006
http://secunia.com/advisories/16985
http://secunia.com/advisories/16309
http://marc.theaimsgroup.com/?l=bugtraq&m=112300046224117&w=2
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt

Copyright 2024, cxsecurity.com

 

Back to Top