20111025 Re: Symlink vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2011/Oct/804 CVE-2011-4089
bzexe (bzip2) - Race Condition
Record summary
CVE-2011-4089 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBbzexe (bzip2) - Race ConditionExploitDB exploitby vladzNot analyzed1 file
References
618147exploit
http://www.exploit-db.com/exploits/18147 [oss-security] 20111028 Re: Request for CVE Identifier: bzexe insecure temporary filemailing list
http://www.openwall.com/lists/oss-security/2011/10/28/16 USN-1308-1Vendor advisory
http://www.ubuntu.com/usn/USN-1308-1 bugs.debian.orgConfirmation
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632862 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-4089