CVE
- Id
- 12194
- CVE No.
- CVE-2005-0988
- Status
- Candidate
- Description
- Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
- Phase
- Assigned (20050406)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
87341 | 12194 | CVE-2005-0988 | BUGTRAQ:20050404 gzip TOCTOU file-permissions vulnerability | View |
87342 | 12194 | CVE-2005-0988 | URL:http://www.securityfocus.com/archive/1/394965 | View |
87343 | 12194 | CVE-2005-0988 | APPLE:APPLE-SA-2006-08-01 | View |
87344 | 12194 | CVE-2005-0988 | URL:http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html | View |
87345 | 12194 | CVE-2005-0988 | DEBIAN:DSA-752 | View |
87346 | 12194 | CVE-2005-0988 | URL:http://www.debian.org/security/2005/dsa-752 | View |
87347 | 12194 | CVE-2005-0988 | REDHAT:RHSA-2005:357 | View |
87348 | 12194 | CVE-2005-0988 | URL:http://rhn.redhat.com/errata/RHSA-2005-357.html | View |
87349 | 12194 | CVE-2005-0988 | SCO:SCOSA-2005.58 | View |
87350 | 12194 | CVE-2005-0988 | URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt | View |
87351 | 12194 | CVE-2005-0988 | SLACKWARE:SSA:2006-262 | View |
87352 | 12194 | CVE-2005-0988 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852 | View |
87353 | 12194 | CVE-2005-0988 | SUNALERT:101816 | View |
87354 | 12194 | CVE-2005-0988 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1 | View |
87355 | 12194 | CVE-2005-0988 | CERT:TA06-214A | View |
87356 | 12194 | CVE-2005-0988 | URL:http://www.us-cert.gov/cas/techalerts/TA06-214A.html | View |
87357 | 12194 | CVE-2005-0988 | BID:12996 | View |
87358 | 12194 | CVE-2005-0988 | URL:http://www.securityfocus.com/bid/12996 | View |
87359 | 12194 | CVE-2005-0988 | BID:19289 | View |
87360 | 12194 | CVE-2005-0988 | URL:http://www.securityfocus.com/bid/19289 | View |
87361 | 12194 | CVE-2005-0988 | OVAL:oval:org.mitre.oval:def:10242 | View |
87362 | 12194 | CVE-2005-0988 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10242 | View |
87363 | 12194 | CVE-2005-0988 | VUPEN:ADV-2006-3101 | View |
87364 | 12194 | CVE-2005-0988 | URL:http://www.vupen.com/english/advisories/2006/3101 | View |
87365 | 12194 | CVE-2005-0988 | OSVDB:15487 | View |
87366 | 12194 | CVE-2005-0988 | URL:http://www.osvdb.org/15487 | View |
87367 | 12194 | CVE-2005-0988 | OVAL:oval:org.mitre.oval:def:1169 | View |
87368 | 12194 | CVE-2005-0988 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1169 | View |
87369 | 12194 | CVE-2005-0988 | OVAL:oval:org.mitre.oval:def:765 | View |
87370 | 12194 | CVE-2005-0988 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:765 | View |
87371 | 12194 | CVE-2005-0988 | SECUNIA:18100 | View |
87372 | 12194 | CVE-2005-0988 | URL:http://secunia.com/advisories/18100 | View |
87373 | 12194 | CVE-2005-0988 | SECUNIA:21253 | View |
87374 | 12194 | CVE-2005-0988 | URL:http://secunia.com/advisories/21253 | View |
87375 | 12194 | CVE-2005-0988 | SECUNIA:22033 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62025 | JVNDB-2005-000227 | GNU sharutils の unshar におけるシンボリックリンク攻撃を受ける脆弱性 | GNU sharutils に含まれている unshar には、セキュリティ上不適切な方法で一時ファイルを作成してしまう不備のため、シンボリックリンク攻撃を受ける脆弱性が存在します。 | CVE-2005-0990 | 12194 | 2.1 | http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000227.html | View |