← Back

CVE-2013-0296

nvd nist
Published: Apr 27, 2014Modified: May 6, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.

Affected (1)

Products: Zlib: Pigz
1 product
Pigz
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.2.4-1

Related CWEs

Timeline

No history available yet.