FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-27 18:04:16 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
9750cf22-216d-11da-bc01-000e0c2e438aunzip -- permission race vulnerability

Imran Ghory reports a vulnerability within unzip. The vulnerability is caused by a race condition between extracting an archive and changing the permissions of the extracted files. This would give an attacker enough time to remove a file and hardlink it to another file owned by the user running unzip. When unzip changes the permissions of the file it could give the attacker access to files that normally would not have been accessible for others.


Discovery 2005-08-02
Entry 2005-09-13
unzip
zh-unzip
ko-unzip
< 5.52_2

14450
CVE-2005-2475
http://marc.theaimsgroup.com/?l=bugtraq&m=112300046224117