cbcvebase.
CVE-2005-0602
published 2005-05-02

CVE-2005-0602: Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.

PriorityP415medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.40%
31.8th percentile
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianunzip< unzip 5.52-1 (bookworm)unzip 5.52-1 (bookworm)
info-zipunzip<= 5.51
info-zipunzip
unzip_projectunzip>= 0 < 5.52-15.52-1
unzip_projectunzip>= 0 < 5.52-15.52-1
unzip_projectunzip>= 0 < 5.52-15.52-1
unzip_projectunzip>= 0 < 5.52-15.52-1

CVSS provenance

nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.