Description
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
Affected products
- FreeBSD / FreeBSD4.6 – 4.6
- FreeBSD / FreeBSD4.7 – 4.7
- FreeBSD / FreeBSD4.7 – 4.7
- FreeBSD / FreeBSD4.7 – 4.7
- FreeBSD / FreeBSD4.7 – 4.7
- FreeBSD / FreeBSD4.8 – 4.8
- FreeBSD / FreeBSD4.8 – 4.8
- FreeBSD / FreeBSD4.8 – 4.8
- FreeBSD / FreeBSD4.8 – 4.8
- FreeBSD / FreeBSD4.9 – 4.9
- FreeBSD / FreeBSD4.9 – 4.9
- FreeBSD / FreeBSD4.9 – 4.9
- FreeBSD / FreeBSD4.10 – 4.10
- FreeBSD / FreeBSD4.10 – 4.10
- FreeBSD / FreeBSD4.10 – 4.10
- FreeBSD / FreeBSD4.10 – 4.10
- FreeBSD / FreeBSD4.11 – 4.11
- FreeBSD / FreeBSD4.11 – 4.11
- FreeBSD / FreeBSD4.11 – 4.11
- FreeBSD / FreeBSD5.0 – 5.0
- FreeBSD / FreeBSD5.0 – 5.0
- FreeBSD / FreeBSD5.0 – 5.0
- FreeBSD / FreeBSD5.0 – 5.0
- FreeBSD / FreeBSD5.1 – 5.1
- FreeBSD / FreeBSD5.1 – 5.1
- FreeBSD / FreeBSD5.1 – 5.1
- FreeBSD / FreeBSD5.1 – 5.1
- FreeBSD / FreeBSD5.1 – 5.1
- FreeBSD / FreeBSD5.2 – 5.2
- FreeBSD / FreeBSD5.2.1 – 5.2.1
- FreeBSD / FreeBSD5.2.1 – 5.2.1
- FreeBSD / FreeBSD5.3 – 5.3
- FreeBSD / FreeBSD5.3 – 5.3
- FreeBSD / FreeBSD5.3 – 5.3
- FreeBSD / FreeBSD5.3 – 5.3
- FreeBSD / FreeBSD5.4 – 5.4
- FreeBSD / FreeBSD5.4 – 5.4
- FreeBSD / FreeBSD5.4 – 5.4
- FreeBSD / FreeBSD4.0 – 4.0
- FreeBSD / FreeBSD4.0 – 4.0
- FreeBSD / FreeBSD4.0 – 4.0
- FreeBSD / FreeBSD4.1 – 4.1
- FreeBSD / FreeBSD4.1.1 – 4.1.1
- FreeBSD / FreeBSD4.1.1 – 4.1.1
- FreeBSD / FreeBSD4.1.1 – 4.1.1
- FreeBSD / FreeBSD4.2 – 4.2
- FreeBSD / FreeBSD4.2 – 4.2
- FreeBSD / FreeBSD4.3 – 4.3
- FreeBSD / FreeBSD4.3 – 4.3
- FreeBSD / FreeBSD4.3 – 4.3
- FreeBSD / FreeBSD4.3 – 4.3
- FreeBSD / FreeBSD4.3 – 4.3
- FreeBSD / FreeBSD4.4 – 4.4
- FreeBSD / FreeBSD4.4 – 4.4
- FreeBSD / FreeBSD4.4 – 4.4
- FreeBSD / FreeBSD4.4 – 4.4
- FreeBSD / FreeBSD4.5 – 4.5
- FreeBSD / FreeBSD4.5 – 4.5
- FreeBSD / FreeBSD4.5 – 4.5
- FreeBSD / FreeBSD4.5 – 4.5
- FreeBSD / FreeBSD4.5 – 4.5
- FreeBSD / FreeBSD4.6 – 4.6
- FreeBSD / FreeBSD4.6 – 4.6
- FreeBSD / FreeBSD4.6 – 4.6
- FreeBSD / FreeBSD4.6 – 4.6
- FreeBSD / FreeBSD4.6.2 – 4.6.2
- FreeBSD / FreeBSD4.7 – 4.7
- gentoo / linux
- gnu / gzip1.3.3 – 1.3.3
- gnu / gzip1.2.4a – 1.2.4a
- gnu / gzip1.2.4 – 1.2.4
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux_desktop4.0 – 4.0
- RedHat / enterprise_linux_desktop3.0 – 3.0
- RedHat / linux_advanced_workstation2.1 – 2.1
- RedHat / linux_advanced_workstation2.1 – 2.1
- trustix / secure_linux2.1 – 2.1
- trustix / secure_linux2.0 – 2.0
- trustix / secure_linux2.2 – 2.2
- turbolinux / turbolinux_appliance_server1.0_hosting – 1.0_hosting
- turbolinux / turbolinux_appliance_server1.0_workgroup – 1.0_workgroup
- turbolinux / turbolinux_desktop10.0 – 10.0
- turbolinux / turbolinux_home
- turbolinux / turbolinux_server10.0 – 10.0
- turbolinux / turbolinux_server7.0 – 7.0
- turbolinux / turbolinux_server8.0 – 8.0
- turbolinux / turbolinux_workstation8.0 – 8.0
- turbolinux / turbolinux_workstation7.0 – 7.0
- Ubuntu / ubuntu_linux5.04 – 5.04
- Ubuntu / ubuntu_linux4.1 – 4.1
- Ubuntu / ubuntu_linux5.04 – 5.04
- Ubuntu / ubuntu_linux5.04 – 5.04
- Ubuntu / ubuntu_linux4.1 – 4.1
References
- MAILING_LISThttp://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/22033
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/3101
- VENDOR_ADVISORYhttp://secunia.com/advisories/21253
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-752
- MISChttp://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1
- MISChttp://rhn.redhat.com/errata/RHSA-2005-357.html
- MISChttp://www.securityfocus.com/bid/19289
- MISChttp://www.us-cert.gov/cas/techalerts/TA06-214A.html
- MISChttp://www.securityfocus.com/bid/12996
- MISChttp://www.osvdb.org/15487
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A765
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10242
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1169
- MISCftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt
- VENDOR_ADVISORYhttp://secunia.com/advisories/18100
- MISChttp://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852
- MISChttp://www.securityfocus.com/archive/1/394965