First published: Fri May 13 2005(Updated: )
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU gzip | <1.3.5 | |
Canonical Ubuntu Linux | =4.10 | |
Canonical Ubuntu Linux | =5.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.