Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-4089Bzip2 vulnerability

CWE-2647 documents7 sources
Severity
4.6MEDIUMNVD
EPSS
0.2%
top 64.22%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 16
Latest updateMay 17

Description

The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

debiandebian/bzip2< bzip2 1.0.6-1 (bookworm)
Debianbzip/bzip2< 1.0.6-1+3
NVDbzip/bzip21.0.4+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f3fh-cjxj-26mw: The bzexe command in bzip2 12022-05-17
OSV
CVE-2011-4089: The bzexe command in bzip2 12014-04-16

💥Exploits & PoCs

1
Exploit-DB
bzexe (bzip2) - Race Condition2011-11-23

📋Vendor Advisories

3
Ubuntu
bzip2 vulnerability2011-12-14
Debian
CVE-2011-4089: bzip2 - The bzexe command in bzip2 1.0.5 and earlier generates compressed executables th...2011
Red Hat
CVE-2011-4089: The bzexe command in bzip2 1
CVE-2011-4089 — Debian Bzip2 vulnerability | cvebase