Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-1271

Опубликовано: 31 авг. 2022
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*
Версия до 1.12 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:tukaani:xz:*:*:*:*:*:*:*:*
Версия до 5.2.5 (исключая)

EPSS

Процентиль: 71%
0.0069
Низкий

8.8 High

CVSS3

Дефекты

CWE-179
CWE-20

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS3: 8.8
redhat
около 3 лет назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS3: 8.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8.8
debian
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep ut ...

suse-cvrf
около 3 лет назад

Security update for gzip

EPSS

Процентиль: 71%
0.0069
Низкий

8.8 High

CVSS3

Дефекты

CWE-179
CWE-20