VulnerabilityModified
CVE-2005-0758
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
MEDIUM 4.6EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Affected
- gnu/gzip · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txtThird Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.ascThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=90626Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=306172Third Party Advisory
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2005-357.htmlThird Party Advisory
- http://secunia.com/advisories/18100Third Party Advisory
- http://secunia.com/advisories/19183Third Party Advisory
- http://secunia.com/advisories/22033Third Party Advisory
- http://secunia.com/advisories/26235Third Party Advisory
- http://securitytracker.com/id?1013928Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852Third Party Advisory
- http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.htmlBroken Link, Permissions Required
- http://www.gentoo.org/security/en/glsa/glsa-200505-05.xmlPatch, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:026Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:027Third Party Advisory
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.htmlThird Party Advisory
- http://www.osvdb.org/16371Broken Link
- http://www.redhat.com/support/errata/RHSA-2005-474.htmlThird Party Advisory
- http://www.securityfocus.com/bid/13582Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25159Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-158-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2732Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20539Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1081Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1107Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9797Third Party Advisory
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txtThird Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.ascThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=90626Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.