CVE-2005-2475: Race Condition
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2475?
The severity of CVE-2005-2475 is rated as Medium due to the potential for unauthorized changes to file permissions.
How do I fix CVE-2005-2475?
To fix CVE-2005-2475, upgrade to a patched version of Unzip that does not have this race condition vulnerability.
Who is affected by CVE-2005-2475?
CVE-2005-2475 affects users of Unzip version 5.52 and potentially those using VISAM VBASE Pro-RT/ Server-RT version 11.6.0.6.
What type of attack does CVE-2005-2475 involve?
CVE-2005-2475 involves a hard link attack that exploits a race condition during file decompression.
What are the potential consequences of CVE-2005-2475?
The potential consequences of CVE-2005-2475 include unauthorized modification of file permissions by local users.