CVE-2005-0953Race Condition in Bzip2

8 documents8 sources
Severity
3.7LOWNVD
EPSS
0.1%
top 73.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 3

Description

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

CVSS vector

AV:L/AC:H/C:P/I:P/A:PExploitability: 1.9 | Impact: 6.4

Affected Packages3 packages

debiandebian/bzip2< bzip2 1.0.2-6 (bookworm)
Debianbzip/bzip2< 1.0.2-6+3
NVDbzip/bzip211 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9fjc-6jmw-8r3m: Race condition in bzip2 12022-05-03
OSV
CVE-2005-0953: Race condition in bzip2 12005-05-02

📋Vendor Advisories

4
BSD
FreeBSD-SA-05:14.bzip2: bzip2 denial of service and permission race vulnerabilities2005-06-29
Ubuntu
bzip2 vulnerabilities2005-05-17
Red Hat
security flaw2005-03-30
Debian
CVE-2005-0953: bzip2 - Race condition in bzip2 1.0.2 and earlier allows local users to modify permissio...2005

💬Community

1
Bugzilla
CVE-2005-0953 security flaw2018-08-16
CVE-2005-0953 — Race Condition in Debian Bzip2 | cvebase