Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-1271

Опубликовано: 31 авг. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

РелизСтатусПримечание
bionic

released

1.6-5ubuntu1.2
devel

released

1.10-4ubuntu4
esm-infra-legacy/trusty

not-affected

1.6-3ubuntu1+esm1
esm-infra/bionic

not-affected

1.6-5ubuntu1.2
esm-infra/focal

not-affected

1.10-0ubuntu4.1
esm-infra/xenial

released

1.6-4ubuntu1+esm1
focal

released

1.10-0ubuntu4.1
impish

released

1.10-4ubuntu1.1
jammy

released

1.10-4ubuntu4
trusty

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

released

5.2.2-1.3ubuntu0.1
devel

released

5.2.5-2ubuntu1
esm-infra-legacy/trusty

not-affected

5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1
esm-infra/bionic

not-affected

5.2.2-1.3ubuntu0.1
esm-infra/focal

not-affected

5.2.4-1ubuntu1.1
esm-infra/xenial

released

5.1.1alpha+20120614-2ubuntu2.16.04.1+esm1
focal

released

5.2.4-1ubuntu1.1
impish

released

5.2.5-2ubuntu0.1
jammy

released

5.2.5-2ubuntu1
trusty/esm

released

5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1

Показывать по

EPSS

Процентиль: 71%
0.0069
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 3 лет назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS3: 8.8
nvd
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS3: 8.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8.8
debian
почти 3 года назад

An arbitrary file write vulnerability was found in GNU gzip's zgrep ut ...

suse-cvrf
около 3 лет назад

Security update for gzip

EPSS

Процентиль: 71%
0.0069
Низкий

8.8 High

CVSS3

Уязвимость CVE-2022-1271