Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

bzip2 Archive Inherited Symbolic Link Permissions Vulnerability

bzip2 is an open-source file compression/decompression utility for Unix and Linux variants.

bzip2 inherits the permissions of symbolic links when a file is compressed, instead of the permissions of the actual file being compressed. The result is that, under some circumstances, when the file is decompressed it will have the permissions of the symbolic link.







 

Privacy Statement
Copyright 2009, SecurityFocus