CVE-1999-1332
published 1999-12-31CVE-1999-1332: gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.40%
32.5th percentile
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gzip | < gzip 1.3.5-6 (bookworm) | gzip 1.3.5-6 (bookworm) |
| debian | gzip | — | — |
| gnu | gzip | <= 1.3.3 | — |
| gzip | gzip | >= 0 < 1.3.5-6 | 1.3.5-6 |
| gzip | gzip | >= 0 < 1.3.5-6 | 1.3.5-6 |
| gzip | gzip | >= 0 < 1.3.5-6 | 1.3.5-6 |
| gzip | gzip | >= 0 < 1.3.5-6 | 1.3.5-6 |
| redhat | linux | <= 5.0 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f955-6xjg-749h: gzexe in the gzip package on Red Hat Linux 5
ghsa_unreviewed·2022-04-30
CVE-1999-1332 [LOW] GHSA-f955-6xjg-749h: gzexe in the gzip package on Red Hat Linux 5
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
GHSA
GHSA-px52-rq5c-w9gw: gzexe in gzip 1
ghsa_unreviewed·2022-04-29·CVSS 2.1
CVE-2004-0603 [LOW] GHSA-px52-rq5c-w9gw: gzexe in gzip 1
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
OSV
CVE-1999-1332: gzexe in the gzip package on Red Hat Linux 5
osv·1999-12-31·CVSS 2.1
CVE-1999-1332 [LOW] CVE-1999-1332: gzexe in the gzip package on Red Hat Linux 5
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
Debian
CVE-2004-0603: gzip - gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a ...
vendor_debian·2004·CVSS 2.1
CVE-2004-0603 [LOW] CVE-2004-0603: gzip - gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a ...
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-1999-1332: gzip - gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to...
vendor_debian·1999·CVSS 2.1
CVE-1999-1332 [LOW] CVE-1999-1332: gzip - gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to...
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
Scope: local
bookworm: resolved (fixed in 1.3.5-6)
bullseye: resolved (fixed in 1.3.5-6)
forky: resolved (fixed in 1.3.5-6)
sid: resolved (fixed in 1.3.5-6)
trixie: resolved (fixed in 1.3.5-6)
Red Hat
CVE-2004-0603: gzexe in gzip 1
vendor_redhat·CVSS 2.1
CVE-2004-0603 [LOW] CVE-2004-0603: gzexe in gzip 1
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=88603844115233&w=2http://www.debian.org/security/2003/dsa-308http://www.iss.net/security_center/static/7241.phphttp://www.osvdb.org/3812http://www.redhat.com/support/errata/rh50-errata-general.html#gziphttp://www.securityfocus.com/bid/7845http://marc.info/?l=bugtraq&m=88603844115233&w=2http://www.debian.org/security/2003/dsa-308http://www.iss.net/security_center/static/7241.phphttp://www.osvdb.org/3812http://www.redhat.com/support/errata/rh50-errata-general.html#gziphttp://www.securityfocus.com/bid/7845
1999-12-31
Published