Vulnerability Description
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Gzip | < 1.3.5 |
| Canonical | Ubuntu Linux | 4.10 |
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txtThird Party Advisory
- ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.ascThird Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=90626Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=306172Third Party Advisory
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2005-357.htmlThird Party Advisory
- http://secunia.com/advisories/18100Third Party Advisory
- http://secunia.com/advisories/19183Third Party Advisory
- http://secunia.com/advisories/22033Third Party Advisory
- http://secunia.com/advisories/26235Third Party Advisory
- http://securitytracker.com/id?1013928Third Party AdvisoryVDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackwareThird Party Advisory
- http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bziBroken LinkPermissions Required
- http://www.gentoo.org/security/en/glsa/glsa-200505-05.xmlPatchThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:026Third Party Advisory
FAQ
What is CVE-2005-0758?
CVE-2005-0758 is a vulnerability with a CVSS score of 4.6 (MEDIUM). zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
How severe is CVE-2005-0758?
CVE-2005-0758 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0758?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Gzip, Canonical Ubuntu Linux.