|
|
Subscribe / Log in / New account

gzip: insecure temporary files

Package(s):gzip CVE #(s):CVE-1999-1332 CAN-2003-0367
Created:June 9, 2003 Updated:June 16, 2003
Description: Paul Szabo discovered that znew, a script included in the gzip package, creates its temporary files without taking precautions to avoid a symlink attack (CAN-2003-0367).

The gzexe script has a similar vulnerability which was patched in an earlier release but inadvertently reverted.

Alerts:
Mandrake MDKSA-2003:068 gzip 2003-06-16
Gentoo 200306-05 gzip 2003-06-14
OpenPKG OpenPKG-SA-2003.031 gzip 2003-06-11
Debian DSA-308-1 gzip 2003-06-06

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds