Oval Definition:oval:org.mitre.oval:tst:30880
Comment:gzip is earlier than 0:1.3.3-12.rhel3
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14444
State:oval:org.mitre.oval:ste:9746
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:9797
V
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
2013-04-29
oval:org.mitre.oval:def:10242
V
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
2013-04-29
oval:org.mitre.oval:def:11057
V
Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
2013-04-29
BACK