← Back

CVE-2005-0988

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
3.7
Vector
AV:L/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 1.9 / Impact: 6.4
Source: NVD

Description

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

Affected (104)

Products: Gnu: Gzip · Freebsd: Freebsd · Gentoo: Linux · +4 more
Show all products
1 product
Gzip
1 product
Freebsd
1 product
Linux
3 products
Enterprise Linux
Enterprise Linux Desktop
Linux Advanced Workstation
1 product
Secure Linux
5 products
Turbolinux Appliance Server
Turbolinux Desktop
Turbolinux Home
Turbolinux Server
Turbolinux Workstation
1 product
Ubuntu Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gnu
Version 1.2.4
Version 1.2.4a
Version 1.3.3
Configuration B
101 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 4.0
Version 4.0 alpha
Version 4.0 releng
Version 4.1.1
Version 4.1.1 release
Version 4.1.1 stable
Version 4.10
Version 4.10 release
Version 4.10 release_p8
Version 4.10 releng
Version 4.11 release_p3
Version 4.11 releng
Version 4.11 stable
Version 4.1
Version 4.2
Version 4.2 stable
Version 4.3
Version 4.3 release
Version 4.3 release_p38
Version 4.3 releng
Version 4.3 stable
Version 4.4
Version 4.4 release_p42
Version 4.4 releng
Version 4.4 stable
Version 4.5
Version 4.5 release
Version 4.5 release_p32
Version 4.5 releng
Version 4.5 stable
Version 4.6.2
Version 4.6
Version 4.6 release
Version 4.6 release_p20
Version 4.6 releng
Version 4.6 stable
Version 4.7
Version 4.7 release
Version 4.7 release_p17
Version 4.7 releng
Version 4.7 stable
Version 4.8
Version 4.8 pre-release
Version 4.8 release_p6
Version 4.8 releng
Version 4.9
Version 4.9 pre-release
Version 4.9 releng
Version 5.0
Version 5.0 alpha
Version 5.0 release_p14
Version 5.0 releng
Version 5.1
Version 5.1 alpha
Version 5.1 release
Version 5.1 release_p5
Version 5.1 releng
Version 5.2.1 release
Version 5.2.1 releng
Version 5.2
Version 5.3
Version 5.3 release
Version 5.3 releng
Version 5.3 stable
Version 5.4 pre-release
Version 5.4 release
Version 5.4 releng
All versions
Redhat
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 3.0
Version 3.0
Version 3.0
Version 4.0
Version 4.0
Version 4.0
Redhat
Version 3.0
Version 4.0
Redhat
Version 2.1
Version 2.1
Trustix
Version 2.0
Version 2.1
Version 2.2
Turbolinux
Version 1.0_hosting
Version 1.0_workgroup
Version 10.0
All versions
Turbolinux
Version 10.0
Version 7.0
Version 8.0
Turbolinux
Version 7.0
Version 8.0
Ubuntu
Version 4.1
Version 4.1
Version 5.04
Version 5.04
Version 5.04

References (36)

ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: cve@mitre.org
US Government Resource
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.