CVE-2005-0602: Medium severity Info-ZIP UnZip vulnerability
Published Mar 1, 2005
·Updated
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
Affected Software
2 affected components
Info-ZIP UnZip<=5.51
Info-ZIP UnZip=5.50
Event History
Mar 1, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0602?
CVE-2005-0602 is classified as a moderate vulnerability that could potentially allow local users to gain higher privileges.
2
How do I fix CVE-2005-0602?
To fix CVE-2005-0602, upgrade your version of Info-ZIP UnZip to 5.52 or later, which includes proper warnings for setuid and setgid files.
3
Who is affected by CVE-2005-0602?
Users of Info-ZIP UnZip versions 5.51 and earlier are primarily affected by CVE-2005-0602.
4
What are the potential impacts of CVE-2005-0602?
The potential impact of CVE-2005-0602 includes unauthorized privilege escalation for local users.
5
Can CVE-2005-0602 be exploited remotely?
No, CVE-2005-0602 requires local access to the affected system to exploit the vulnerability.