CVE-2005-0602
published 2005-05-02CVE-2005-0602: Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
PriorityP415medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.40%
31.8th percentile
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | unzip | < unzip 5.52-1 (bookworm) | unzip 5.52-1 (bookworm) |
| info-zip | unzip | <= 5.51 | — |
| info-zip | unzip | — | — |
| unzip_project | unzip | >= 0 < 5.52-1 | 5.52-1 |
| unzip_project | unzip | >= 0 < 5.52-1 | 5.52-1 |
| unzip_project | unzip | >= 0 < 5.52-1 | 5.52-1 |
| unzip_project | unzip | >= 0 < 5.52-1 | 5.52-1 |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
unzip vulnerability
vendor_ubuntu·2005-08-01
CVE-2005-0602 unzip vulnerability
Title: unzip vulnerability
Summary: unzip vulnerability
If a ZIP archive contains binaries with the setuid and/or setgid bit
set, unzip preserved those bits when extracting the archive. This
could be exploited by tricking the administrator into unzipping an
archive with a setuid-root binary into a directory the attacker can
access. This allowed the attacker to execute arbitrary commands with
root privileges.
The updated version does not preserve setuid, setgid, and sticky bits
any more by default. The old behaviour can be explicitly requested now
by supplying the option '-K'.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2005-0602: unzip - Unzip 5.51 and earlier does not properly warn the user when extracting setuid or...
vendor_debian·2005·CVSS 6.2
CVE-2005-0602 [MEDIUM] CVE-2005-0602: unzip - Unzip 5.51 and earlier does not properly warn the user when extracting setuid or...
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
Scope: local
bookworm: resolved (fixed in 5.52-1)
bullseye: resolved (fixed in 5.52-1)
forky: resolved (fixed in 5.52-1)
sid: resolved (fixed in 5.52-1)
trixie: resolved (fixed in 5.52-1)
Red Hat
CVE-2005-0602: Unzip 5
vendor_redhat·CVSS 6.2
CVE-2005-0602 [MEDIUM] CVE-2005-0602: Unzip 5
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
Statement: We do not consider this a security vulnerability; this is the expected behaviour.
GHSA
GHSA-h78h-jj63-v974: Unzip 5
ghsa_unreviewed·2022-05-01
CVE-2005-0602 [MEDIUM] GHSA-h78h-jj63-v974: Unzip 5
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
OSV
CVE-2005-0602: Unzip 5
osv·2005-05-02·CVSS 6.2
CVE-2005-0602 [MEDIUM] CVE-2005-0602: Unzip 5
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=110960796331943&w=2http://secunia.com/advisories/17045http://secunia.com/advisories/17342http://secunia.com/advisories/27684http://sunsolve.sun.com/search/document.do?assetkey=1-26-103150-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200844-1http://www.info-zip.org/FAQ.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:197http://www.securityfocus.com/bid/14447http://www.trustix.org/errata/2005/0053/http://www.vupen.com/english/advisories/2007/3866http://marc.info/?l=bugtraq&m=110960796331943&w=2http://secunia.com/advisories/17045http://secunia.com/advisories/17342http://secunia.com/advisories/27684http://sunsolve.sun.com/search/document.do?assetkey=1-26-103150-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200844-1http://www.info-zip.org/FAQ.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:197http://www.securityfocus.com/bid/14447http://www.trustix.org/errata/2005/0053/http://www.vupen.com/english/advisories/2007/3866
2005-05-02
Published