Description
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.
CVSS vector
AV:L/AC:H/C:P/I:N/A:NExploitability: 1.9 | Impact: 2.9Complexity: High
Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-3m3m-6r6c-8m58: Race condition in Unzip 5↗2022-05-03 ▶ OSVCVE-2005-2475: Race condition in Unzip 5↗2005-08-05 ▶ CVEListCVE-2005-2475: Race condition in Unzip 5↗2005-08-05 ▶ 📋Vendor Advisories
3Ubuntuunzip vulnerability↗2005-09-30 ▶ Red Hatsecurity flaw↗2005-08-02 ▶ DebianCVE-2005-2475: unzip - Race condition in Unzip 5.52 allows local users to modify permissions of arbitra...↗2005 ▶ 💬Community
4BugzillaCVE-2005-2475 security flaw↗2018-08-16 ▶ BugzillaCVE-2005-2475 TOCTOU issue in unzip↗2007-02-19 ▶ BugzillaCVE-2005-2475 TOCTOU issue in unzip↗2007-02-01 ▶ BugzillaCVE-2005-2475 TOCTOU issue in unzip↗2005-08-02 ▶