CVE-2004-0603
published 2004-12-06CVE-2004-0603: gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote…
PriorityP432critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.13%
86.3th percentile
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gzip | — | — |
| gnu | gzip | <= 1.3.3 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2004-0603: gzip - gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a ...
vendor_debian·2004·CVSS 2.1
CVE-2004-0603 [LOW] CVE-2004-0603: gzip - gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a ...
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
CVE-2004-0603: gzexe in gzip 1
vendor_redhat·CVSS 2.1
CVE-2004-0603 [LOW] CVE-2004-0603: gzexe in gzip 1
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
GHSA
GHSA-px52-rq5c-w9gw: gzexe in gzip 1
ghsa_unreviewed·2022-04-29·CVSS 2.1
CVE-2004-0603 [LOW] GHSA-px52-rq5c-w9gw: gzexe in gzip 1
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=54890http://security.gentoo.org/glsa/glsa-200406-18.xmlhttp://www.securityfocus.com/bid/10603https://exchange.xforce.ibmcloud.com/vulnerabilities/16506http://bugs.gentoo.org/show_bug.cgi?id=54890http://security.gentoo.org/glsa/glsa-200406-18.xmlhttp://www.securityfocus.com/bid/10603https://exchange.xforce.ibmcloud.com/vulnerabilities/16506
2004-12-06
Published