gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2004-10-04 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-1349
Mitre link : CVE-2004-1349
CVE.ORG link : CVE-2004-1349
JSON object : View
Products Affected
oracle
- solaris
gnu
- gzip
CWE
CWE-269
Improper Privilege Management