CVE-2005-0758

11 documents8 sources
Severity
4.6MEDIUM
EPSS
0.2%
top 59.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 3

Description

zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

NVDgnu/gzip< 1.3.5
Debiangzip< 1.3.5-10+3
Debianbzip2< 1.0.2-8.1+3

Also affects: Ubuntu Linux 4.10, 5.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gc4q-mf7x-jrrp: zgrep in gzip before 12022-05-03
CVEList
CVE-2005-0758: zgrep in gzip before 12005-05-13
OSV
CVE-2005-0758: zgrep in gzip before 12005-05-13

📋Vendor Advisories

4
Ubuntu
bzip2 utility vulnerability2005-08-05
Ubuntu
gzip utility vulnerability2005-08-01
Red Hat
security flaw2005-04-22
Debian
CVE-2005-0758: bzip2 - zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows lo...2005

💬Community

2
Bugzilla
CVE-2005-0758 security flaw2018-08-16
Bugzilla
CVE-2005-0758 bzgrep has security issue in sed usage2005-06-08