CVE-2005-2475

Impact:
Low
Public Date:
2005-08-02
Bugzilla:
1617723: CVE-2005-2475 security flaw

The MITRE CVE dictionary describes this issue as:

Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

Find out more about CVE-2005-2475 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue was addressed in unzip packages as shipped with Red Hat Enterprise Linux 3 and 4 via RHBA-2007:0418 and RHSA-2007:0203 respectively.

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 3 (unzip) RHBA-2007:0418 2007-07-11
Red Hat Enterprise Linux 4 (unzip) RHSA-2007:0203 2007-05-01

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.