LWN.net Logo

pigz: information disclosure

Package(s):pigz CVE #(s):CVE-2013-0296
Created:February 26, 2013 Updated:March 27, 2013
Description: From the Red Hat bugzilla:

A security flaw was found in the way pigz, a parallel implementation of gzip, created temporary files to (temporary) store / represent 'to be compressed archive content' (the files were created with world readable permissions). A local attacker could use this flaw to obtain sensitive information (archive content).

Alerts:
Fedora FEDORA-2013-2589 2013-02-26
openSUSE openSUSE-SU-2013:0540-1 2013-03-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds