FreeBSD : unzip -- permission race vulnerability (9750cf22-216d-11da-bc01-000e0c2e438a)

low Nessus Plugin ID 21480

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Imran Ghory reports a vulnerability within unzip. The vulnerability is caused by a race condition between extracting an archive and changing the permissions of the extracted files. This would give an attacker enough time to remove a file and hardlink it to another file owned by the user running unzip. When unzip changes the permissions of the file it could give the attacker access to files that normally would not have been accessible for others.

Solution

Update the affected packages.

See Also

https://marc.info/?l=bugtraq&m=112300046224117

http://www.nessus.org/u?39e76123

Plugin Details

Severity: Low

ID: 21480

File Name: freebsd_pkg_9750cf22216d11dabc01000e0c2e438a.nasl

Version: 1.16

Type: local

Published: 5/13/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Low

Base Score: 1.2

Temporal Score: 1

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:ko-unzip, p-cpe:/a:freebsd:freebsd:unzip, p-cpe:/a:freebsd:freebsd:zh-unzip, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/13/2005

Vulnerability Publication Date: 8/2/2005

Reference Information

CVE: CVE-2005-2475

BID: 14450