Описание
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Отчет
This bug was introduced in gzip-1.3.10 and is relatively hard to exploit. Red Hat Enterprise Linux 6 was affected but Out of Support Cycle because gzip was not listed in Red Hat Enterprise Linux 6 ELS Inclusion List. https://access.redhat.com/articles/4997301
Меры по смягчению последствий
Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gzip | Out of support scope | ||
Red Hat Enterprise Linux 6 | xz | Out of support scope | ||
Red Hat JBoss Data Grid 7 | gzip | Affected | ||
Red Hat Enterprise Linux 7 | gzip | Fixed | RHSA-2022:2191 | 11.05.2022 |
Red Hat Enterprise Linux 7 | xz | Fixed | RHSA-2022:5052 | 15.06.2022 |
Red Hat Enterprise Linux 8 | gzip | Fixed | RHSA-2022:1537 | 26.04.2022 |
Red Hat Enterprise Linux 8 | xz | Fixed | RHSA-2022:4991 | 13.06.2022 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | gzip | Fixed | RHSA-2022:1592 | 26.04.2022 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | xz | Fixed | RHSA-2022:4994 | 13.06.2022 |
Red Hat Enterprise Linux 8.2 Extended Update Support | gzip | Fixed | RHSA-2022:1665 | 02.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
An arbitrary file write vulnerability was found in GNU gzip's zgrep ut ...
EPSS
8.8 High
CVSS3