CVE-2022-1271

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
gnugzip
𝑥
< 1.12
redhatjboss_data_grid
7.0.0
debiandebian_linux
10.0
tukaanixz
𝑥
< 5.2.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gzip
bullseye (security)
1.10-4+deb11u1
fixed
bullseye
1.10-4+deb11u1
fixed
bookworm
1.12-1
fixed
sid
1.12-1.1
fixed
trixie
1.12-1.1
fixed
xz-utils
bullseye (security)
5.2.5-2.1~deb11u1
fixed
bullseye
5.2.5-2.1~deb11u1
fixed
bookworm
5.4.1-0.2
fixed
sid
5.6.3-1
fixed
trixie
5.6.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gzip
jammy
Fixed 1.10-4ubuntu4
released
impish
Fixed 1.10-4ubuntu1.1
released
focal
Fixed 1.10-0ubuntu4.1
released
bionic
Fixed 1.6-5ubuntu1.2
released
xenial
Fixed 1.6-4ubuntu1+esm1
released
trusty
Fixed 1.6-3ubuntu1+esm1
released
xz-utils
jammy
Fixed 5.2.5-2ubuntu1
released
impish
Fixed 5.2.5-2ubuntu0.1
released
focal
Fixed 5.2.4-1ubuntu1.1
released
bionic
Fixed 5.2.2-1.3ubuntu0.1
released
xenial
Fixed 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm1
released
trusty
Fixed 5.1.1alpha+20120614-2ubuntu2.14.04.1+esm1
released