Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rcq-48gc-62g8

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions before setting the permissions to what is specified in the bzip2 archive, which could allow local users to read the files as they are being decompressed.

Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions before setting the permissions to what is specified in the bzip2 archive, which could allow local users to read the files as they are being decompressed.

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

nvd
больше 23 лет назад

Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions before setting the permissions to what is specified in the bzip2 archive, which could allow local users to read the files as they are being decompressed.

EPSS

Процентиль: 31%
0.00115
Низкий