CVE-2005-0602Unzip vulnerability

7 documents7 sources
Severity
6.2MEDIUMNVD
EPSS
0.1%
top 65.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages2 packages

Debianunzip_project/unzip< 5.52-1+3
NVDinfo-zip/unzip5.51+1

🔴Vulnerability Details

3
GHSA
GHSA-h78h-jj63-v974: Unzip 52022-05-01
OSV
CVE-2005-0602: Unzip 52005-05-02
CVEList
CVE-2005-0602: Unzip 52005-03-01

📋Vendor Advisories

3
Ubuntu
unzip vulnerability2005-08-01
Debian
CVE-2005-0602: unzip - Unzip 5.51 and earlier does not properly warn the user when extracting setuid or...2005
Red Hat
CVE-2005-0602: Unzip 5
CVE-2005-0602 — Info-zip Unzip vulnerability | cvebase