Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2005-0758
Disclosure Date: May 13, 2005 (last updated February 22, 2025)
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
0
Attacker Value
Unknown
CVE-2005-0988
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
0
Attacker Value
Unknown
CVE-2005-1228
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
0
Attacker Value
Unknown
CVE-2004-0970
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
0
Attacker Value
Unknown
CVE-2004-0603
Disclosure Date: December 06, 2004 (last updated February 22, 2025)
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
0
Attacker Value
Unknown
CVE-2004-1349
Disclosure Date: October 04, 2004 (last updated February 22, 2025)
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
0
Attacker Value
Unknown
CVE-2003-0844
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
0
Attacker Value
Unknown
CVE-2003-0842
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.
0
Attacker Value
Unknown
CVE-2003-0843
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
0
Attacker Value
Unknown
CVE-2003-0367
Disclosure Date: July 02, 2003 (last updated February 22, 2025)
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0