Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1271

Опубликовано: 07 апр. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

Отчет

This bug was introduced in gzip-1.3.10 and is relatively hard to exploit. Red Hat Enterprise Linux 6 was affected but Out of Support Cycle because gzip was not listed in Red Hat Enterprise Linux 6 ELS Inclusion List. https://access.redhat.com/articles/4997301

Меры по смягчению последствий

Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gzipOut of support scope
Red Hat Enterprise Linux 6xzOut of support scope
Red Hat JBoss Data Grid 7gzipAffected
Red Hat Enterprise Linux 7gzipFixedRHSA-2022:219111.05.2022
Red Hat Enterprise Linux 7xzFixedRHSA-2022:505215.06.2022
Red Hat Enterprise Linux 8gzipFixedRHSA-2022:153726.04.2022
Red Hat Enterprise Linux 8xzFixedRHSA-2022:499113.06.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsgzipFixedRHSA-2022:159226.04.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsxzFixedRHSA-2022:499413.06.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportgzipFixedRHSA-2022:166502.05.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-179
Дефект:
CWE-1173
https://bugzilla.redhat.com/show_bug.cgi?id=2073310gzip: arbitrary-file-write vulnerability

EPSS

Процентиль: 71%
0.0069
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS3: 8.8
nvd
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS3: 8.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8.8
debian
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep ut ...

suse-cvrf
около 3 лет назад

Security update for gzip

EPSS

Процентиль: 71%
0.0069
Низкий

8.8 High

CVSS3