CVE-2011-4089
16.04.2014, 18:37
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bzip | bzip2 | 𝑥 ≤ 1.0.4 |
| bzip | bzip2 | 1.0 |
| bzip | bzip2 | 1.0.1 |
| bzip | bzip2 | 1.0.2 |
| bzip | bzip2 | 1.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References