CVE-2015-1200

pxz 4.999.99 Beta 3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100207
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2015/q1/177
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72101

Scores

EPSS 0.0028
EPSS Percentile 19.6%

Details

CWE
CWE-362
Status published
Products (1)
pxz_project/pxz 4.999.99 beta3
Published Jan 23, 2015
Tracked Since Feb 18, 2026