Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-0953

Опубликовано: 02 мая 2005
Источник: debian
EPSS Низкий

Описание

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bzip2fixed1.0.2-6package

Примечания

  • This "vulnerability" is only exploitable under rarest circumstances: A (local)

  • attacker would have to exploit the minimal time span between uncompressing

  • the file and chmodding it to delete the file and place a hardlink to another

  • file of the "attacked" user. Additionally the attacker needs write permissions

  • to the directory where the file is being uncompressed, ruling out /~ etc.

EPSS

Процентиль: 27%
0.00094
Низкий

Связанные уязвимости

ubuntu
больше 20 лет назад

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

redhat
больше 20 лет назад

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

nvd
больше 20 лет назад

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

github
больше 3 лет назад

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

EPSS

Процентиль: 27%
0.00094
Низкий