gzip: arbitrary-file-write vulnerability
Published Aug 31, 2022
8.8
HIGHCVSS 3.1
EPSS 5.07%
Description
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Affected products
- Vendor n/a Product Gzip, XZ-Utils Defaultn/a
- Version Fixed in gzip 1.12StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Gzip, XZ-Utils | n/a |
|
Configuration 2
- 7.0.0
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 7
gzip-0:1.5-11.el7_9
Fixed · RHSA-2022:2191
Red Hat Enterprise Linux 7
xz-0:5.2.2-2.el7_9
Fixed · RHSA-2022:5052
Red Hat Enterprise Linux 8
gzip-0:1.9-13.el8_5
Fixed · RHSA-2022:1537
Red Hat Enterprise Linux 8
xz-0:5.2.4-4.el8_6
Fixed · RHSA-2022:4991
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
gzip-0:1.9-10.el8_1
Fixed · RHSA-2022:1592
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
xz-0:5.2.4-4.el8_1
Fixed · RHSA-2022:4994
Red Hat Enterprise Linux 8.2 Extended Update Support
gzip-0:1.9-10.el8_2
Fixed · RHSA-2022:1665
Red Hat Enterprise Linux 8.2 Extended Update Support
xz-0:5.2.4-4.el8_2
Fixed · RHSA-2022:4992
Red Hat Enterprise Linux 8.4 Extended Update Support
gzip-0:1.9-13.el8_4
Fixed · RHSA-2022:1676
Red Hat Enterprise Linux 8.4 Extended Update Support
xz-0:5.2.4-4.el8_4
Fixed · RHSA-2022:4993
Red Hat Enterprise Linux 9
gzip-0:1.10-9.el9_0
Fixed · RHSA-2022:4582
Red Hat Enterprise Linux 9
xz-0:5.2.5-8.el9_0
Fixed · RHSA-2022:4940
Red Hat Enterprise Linux 9
xz-0:5.2.5-8.el9_0
Fixed · RHSA-2022:4940
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.23-20220622.0.el7_9
Fixed · RHSA-2022:5439
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.0-202205291010_8.6
Fixed · RHSA-2022:4896
Red Hat Enterprise Linux 6
gzip
Out of support scope
Red Hat Enterprise Linux 6
xz
Out of support scope
Red Hat JBoss Data Grid 7
gzip
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | gzip-0:1.5-11.el7_9 | Fixed | RHSA-2022:2191 |
| Red Hat Enterprise Linux 7 | xz-0:5.2.2-2.el7_9 | Fixed | RHSA-2022:5052 |
| Red Hat Enterprise Linux 8 | gzip-0:1.9-13.el8_5 | Fixed | RHSA-2022:1537 |
| Red Hat Enterprise Linux 8 | xz-0:5.2.4-4.el8_6 | Fixed | RHSA-2022:4991 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | gzip-0:1.9-10.el8_1 | Fixed | RHSA-2022:1592 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | xz-0:5.2.4-4.el8_1 | Fixed | RHSA-2022:4994 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | gzip-0:1.9-10.el8_2 | Fixed | RHSA-2022:1665 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | xz-0:5.2.4-4.el8_2 | Fixed | RHSA-2022:4992 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | gzip-0:1.9-13.el8_4 | Fixed | RHSA-2022:1676 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | xz-0:5.2.4-4.el8_4 | Fixed | RHSA-2022:4993 |
| Red Hat Enterprise Linux 9 | gzip-0:1.10-9.el9_0 | Fixed | RHSA-2022:4582 |
| Red Hat Enterprise Linux 9 | xz-0:5.2.5-8.el9_0 | Fixed | RHSA-2022:4940 |
| Red Hat Enterprise Linux 9 | xz-0:5.2.5-8.el9_0 | Fixed | RHSA-2022:4940 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.23-20220622.0.el7_9 | Fixed | RHSA-2022:5439 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.0-202205291010_8.6 | Fixed | RHSA-2022:4896 |
| Red Hat Enterprise Linux 6 | gzip | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | xz | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | gzip | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This bug was introduced in gzip-1.3.10 and is relatively hard to exploit. Red Hat Enterprise Linux 6 was affected but Out of Support Cycle because gzip was not listed in Red Hat Enterprise Linux 6 ELS Inclusion List. https://access.redhat.com/articles/4997301
Red Hat mitigation
Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (12)
- https://access.redhat.com/security/cve/CVE-2022-1271 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2073310 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24604 Advisory
- https://git.tukaani.org/?p=xz.git%3Ba=commit%3Bh=69d1b3fc29677af8ade8dc15dba83f0589cb63d6 x_refsource_MISCBroken Link
- https://lists.gnu.org/r/bug-gzip/2022-04/msg00011.html x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1271
- https://security-tracker.debian.org/tracker/CVE-2022-1271 x_refsource_MISCThird Party Advisory
- https://security.gentoo.org/glsa/202209-01 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220930-0006/ x_refsource_CONFIRMThird Party Advisory
- https://tukaani.org/xz/xzgrep-ZDI-CAN-16587.patch x_refsource_MISCPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1271
- https://www.openwall.com/lists/oss-security/2022/04/07/8 x_refsource_MISCMailing ListPatchThird Party Advisory
Change history (0)
No recorded changes yet.