LOW
security flaw
Published Apr 6, 2005
3.7
LOWCVSS 2.0
EPSS 0.66%
Description
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 4.0
- 4.0
- 4.0
- 4.1
- 4.1.1
- 4.1.1
- 4.1.1
- 4.2
- 4.2
- 4.3
- 4.3
- 4.3
- 4.3
- 4.3
- 4.4
- 4.4
- 4.4
- 4.4
- 4.5
- 4.5
- 4.5
- 4.5
- 4.5
- 4.6
- 4.6
- 4.6
- 4.6
- 4.6
- 4.6.2
- 4.7
- 4.7
- 4.7
- 4.7
- 4.7
- 4.8
- 4.8
- 4.8
- 4.8
- 4.9
- 4.9
- 4.9
- 4.10
- 4.10
- 4.10
- 4.10
- 4.11
- 4.11
- 4.11
- 5.0
- 5.0
- 5.0
- 5.0
- 5.1
- 5.1
- 5.1
- 5.1
- 5.1
- 5.2
- 5.2.1
- 5.2.1
- 5.3
- 5.3
- 5.3
- 5.3
- 5.4
- 5.4
- 5.4
- n/a
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 3.0
- 3.0
- 3.0
- 4.0
- 4.0
- 4.0
- 3.0
- 4.0
- 2.1
- 2.1
- 2.0
- 2.1
- 2.2
- 1.0_hosting
- 1.0_workgroup
- 10.0
- n/a
- 7.0
- 8.0
- 10.0
- 7.0
- 8.0
- 4.1
- 4.1
- 5.04
- 5.04
- 5.04
No data.
Red Hat Enterprise Linux 3
gzip-0:1.3.3-12.rhel3
Fixed · RHSA-2005:357
Red Hat Enterprise Linux 4
gzip-0:1.3.3-15.rhel4
Fixed · RHSA-2005:357
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | gzip-0:1.3.3-12.rhel3 | Fixed | RHSA-2005:357 |
| Red Hat Enterprise Linux 4 | gzip-0:1.3.3-15.rhel4 | Fixed | RHSA-2005:357 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Weaknesses (0)
No CWE recorded.
References (23)
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt vendor-advisoryx_refsource_SCO
- http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html vendor-advisoryx_refsource_APPLE
- http://rhn.redhat.com/errata/RHSA-2005-357.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/18100 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21253 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22033 third-party-advisoryx_refsource_SECUNIA
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1 vendor-advisoryx_refsource_SUNALERT
- http://www.debian.org/security/2005/dsa-752 vendor-advisoryx_refsource_DEBIAN
- http://www.osvdb.org/15487 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/394965 mailing-listx_refsource_BUGTRAQVendor Advisory
- http://www.securityfocus.com/bid/12996 vdb-entryx_refsource_BIDPatch
- http://www.securityfocus.com/bid/19289 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA06-214A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/3101 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-0988 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617595 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0989 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-0988
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10242 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1169 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A765 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-0988
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 6, 2005
Updated Aug 7, 2024
Reserved Apr 6, 2005
Link CVE-2005-0988
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2005-0989 Assigner mitre
Published Apr 6, 2005
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2005-0989