CVE-2005-1228

Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
References
Link Resource
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255 Patch
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
http://marc.info/?l=bugtraq&m=111402732406477&w=2
http://rhn.redhat.com/errata/RHSA-2005-357.html
http://secunia.com/advisories/15047 Vendor Advisory
http://secunia.com/advisories/18100
http://secunia.com/advisories/21253
http://secunia.com/advisories/22033
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1
http://www.debian.org/security/2005/dsa-752
http://www.osvdb.org/15721
http://www.securityfocus.com/bid/19289
http://www.us-cert.gov/cas/techalerts/TA06-214A.html US Government Resource
http://www.vupen.com/english/advisories/2006/3101
https://exchange.xforce.ibmcloud.com/vulnerabilities/20199
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11057
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A170
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A382
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255 Patch
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html
http://marc.info/?l=bugtraq&m=111402732406477&w=2
http://rhn.redhat.com/errata/RHSA-2005-357.html
http://secunia.com/advisories/15047 Vendor Advisory
http://secunia.com/advisories/18100
http://secunia.com/advisories/21253
http://secunia.com/advisories/22033
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1
http://www.debian.org/security/2005/dsa-752
http://www.osvdb.org/15721
http://www.securityfocus.com/bid/19289
http://www.us-cert.gov/cas/techalerts/TA06-214A.html US Government Resource
http://www.vupen.com/english/advisories/2006/3101
https://exchange.xforce.ibmcloud.com/vulnerabilities/20199
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11057
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A170
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A382
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:gzip:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gzip:1.3.3:*:*:*:*:*:*:*

History

20 Nov 2024, 23:56

Type Values Removed Values Added
References () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt - () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt -
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255 - Patch () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255 - Patch
References () http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html - () http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html -
References () http://marc.info/?l=bugtraq&m=111402732406477&w=2 - () http://marc.info/?l=bugtraq&m=111402732406477&w=2 -
References () http://rhn.redhat.com/errata/RHSA-2005-357.html - () http://rhn.redhat.com/errata/RHSA-2005-357.html -
References () http://secunia.com/advisories/15047 - Vendor Advisory () http://secunia.com/advisories/15047 - Vendor Advisory
References () http://secunia.com/advisories/18100 - () http://secunia.com/advisories/18100 -
References () http://secunia.com/advisories/21253 - () http://secunia.com/advisories/21253 -
References () http://secunia.com/advisories/22033 - () http://secunia.com/advisories/22033 -
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1 -
References () http://www.debian.org/security/2005/dsa-752 - () http://www.debian.org/security/2005/dsa-752 -
References () http://www.osvdb.org/15721 - () http://www.osvdb.org/15721 -
References () http://www.securityfocus.com/bid/19289 - () http://www.securityfocus.com/bid/19289 -
References () http://www.us-cert.gov/cas/techalerts/TA06-214A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-214A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/3101 - () http://www.vupen.com/english/advisories/2006/3101 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/20199 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/20199 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11057 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11057 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A170 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A170 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A382 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A382 -

Information

Published : 2005-05-02 04:00

Updated : 2024-11-20 23:56


NVD link : CVE-2005-1228

Mitre link : CVE-2005-1228

CVE.ORG link : CVE-2005-1228


JSON object : View

Products Affected

gnu

  • gzip