First published: Fri Aug 05 2005(Updated: )
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Info-ZIP Zip | =5.52 | |
VISAM VBASE | =11.6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2475 is rated as Medium due to the potential for unauthorized changes to file permissions.
To fix CVE-2005-2475, upgrade to a patched version of Unzip that does not have this race condition vulnerability.
CVE-2005-2475 affects users of Unzip version 5.52 and potentially those using VISAM VBASE Pro-RT/ Server-RT version 11.6.0.6.
CVE-2005-2475 involves a hard link attack that exploits a race condition during file decompression.
The potential consequences of CVE-2005-2475 include unauthorized modification of file permissions by local users.