Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2005-0953

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

  • Published: May 2, 2005
  • Updated: Apr 13, 2023
  • CVE: CVE-2005-0953
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 3.7
  • AV:L/AC:H/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
bzip / bzip2 1.0 1.0.x
bzip / bzip2 0.9.5_a 0.9.5_a.x
bzip / bzip2 0.9.5_d 0.9.5_d.x
bzip / bzip2 0.9.5_c 0.9.5_c.x
bzip / bzip2 0.9_a 0.9_a.x
bzip / bzip2 0.9_c 0.9_c.x
bzip / bzip2 1.0.2 1.0.2.x
bzip / bzip2 0.9 0.9.x
bzip / bzip2 1.0.1 1.0.1.x
bzip / bzip2 0.9_b 0.9_b.x
bzip / bzip2 0.9.5_b 0.9.5_b.x