CVE-2013-0296

high

Description

Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.

References

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700608

http://www.openwall.com/lists/oss-security/2013/02/16/3

http://www.openwall.com/lists/oss-security/2013/02/15/4

http://mail.zlib.net/pipermail/pigz-announce_zlib.net/2012-July/000006.html

http://lists.opensuse.org/opensuse-updates/2013-03/msg00106.html

Details

Source: Mitre, NVD

Published: 2014-04-27

Updated: 2014-04-28

Risk Information

CVSS v2

Base Score: 4.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High