Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2005-0758

Disclosure Date: May 13, 2005 (last updated February 22, 2025)
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
0
Attacker Value
Unknown

CVE-2005-0988

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
0
Attacker Value
Unknown

CVE-2005-1228

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
0
Attacker Value
Unknown

CVE-2004-0970

Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
0
Attacker Value
Unknown

CVE-2004-0603

Disclosure Date: December 06, 2004 (last updated February 22, 2025)
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
0
Attacker Value
Unknown

CVE-2004-1349

Disclosure Date: October 04, 2004 (last updated February 22, 2025)
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
0
Attacker Value
Unknown

CVE-2003-0844

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.
Attacker Value
Unknown

CVE-2003-0842

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.
0
Attacker Value
Unknown

CVE-2003-0843

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.
0
Attacker Value
Unknown

CVE-2003-0367

Disclosure Date: July 02, 2003 (last updated February 22, 2025)
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0