CVE-2004-0970
published 2005-02-09CVE-2004-0970: The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.36%
28.7th percentile
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gzip | < gzip 1.3.5-8 (bookworm) | gzip 1.3.5-8 (bookworm) |
| debian | ncompress | — | — |
| gnu | gzip | — | — |
| gzip | gzip | >= 0 < 1.3.5-8 | 1.3.5-8 |
| gzip | gzip | >= 0 < 1.3.5-8 | 1.3.5-8 |
| gzip | gzip | >= 0 < 1.3.5-8 | 1.3.5-8 |
| gzip | gzip | >= 0 < 1.3.5-8 | 1.3.5-8 |
| ncompress | ncompress | <= 4.2.4_r1 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1MEDIUM
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ncompress: insecure tmp file handling may lead to file overwrite
vendor_redhat·2021-11-09·CVSS 2.1
CVE-2005-2991 [LOW] CWE-59 ncompress: insecure tmp file handling may lead to file overwrite
ncompress: insecure tmp file handling may lead to file overwrite
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
Statement: Not vulnerable. This issue did not affect the ncompress packages as distributed with Red Hat Enterprise Linux 2.1, 3, or 4.
Package: ncompress (Red Hat Enterprise Linux 6) - Not affected
Package: ncompress (Red Hat Enterprise Linux 7) - Not affected
Package: ncompress (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2005-2991: ncompress - ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via ...
vendor_debian·2005·CVSS 2.1
CVE-2005-2991 [LOW] CVE-2005-2991: ncompress - ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via ...
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2004-0970: gzip - The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by o...
vendor_debian·2004·CVSS 2.1
CVE-2004-0970 [LOW] CVE-2004-0970: gzip - The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by o...
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
Scope: local
bookworm: resolved (fixed in 1.3.5-8)
bullseye: resolved (fixed in 1.3.5-8)
forky: resolved (fixed in 1.3.5-8)
sid: resolved (fixed in 1.3.5-8)
trixie: resolved (fixed in 1.3.5-8)
GHSA
GHSA-fh95-qp78-39wf: ncompress 4
ghsa_unreviewed·2022-05-01·CVSS 2.1
CVE-2005-2991 [LOW] GHSA-fh95-qp78-39wf: ncompress 4
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
GHSA
GHSA-2jrh-9rrj-2f59: The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files
ghsa_unreviewed·2022-04-29·CVSS 2.1
CVE-2004-0970 [LOW] GHSA-2jrh-9rrj-2f59: The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
OSV
CVE-2004-0970: The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files
osv·2005-02-09·CVSS 2.1
CVE-2004-0970 [LOW] CVE-2004-0970: The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/13131http://www.debian.org/security/2004/dsa-588http://www.securityfocus.com/bid/11288http://www.trustix.org/errata/2004/0050http://www.zataz.net/adviso/ncompress-09052005.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/17583http://secunia.com/advisories/13131http://www.debian.org/security/2004/dsa-588http://www.securityfocus.com/bid/11288http://www.trustix.org/errata/2004/0050http://www.zataz.net/adviso/ncompress-09052005.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/17583
2005-02-09
Published