Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

bzip2 chmod File Permission Modification Race Condition Weakness

The 'bzip2' utility is reported prone to a security weakness that is present only when an archive is extracted into a world- or group-writeable directory. Reportedly, bzip2 employs nonatomic procedures to write a file and later changes the permissions on the newly extracted file.

A local attacker may leverage this issue to modify file permissions of target files.

This weakness is reported to affect bzip2 1.0.2 and previous versions.







 

Privacy Statement
Copyright 2008, SecurityFocus