[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-1200Date: (C)2015-01-27   (M)2023-12-22


Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-72101
FEDORA-2020-07fcbfddbd
FEDORA-2020-8b89d5b9eb
FEDORA-2020-c9eb911737
http://seclists.org/oss-sec/2015/q1/177
pxz-cve20151200-sec-bypass(100207)

CPE    1
cpe:/a:pxz_project:pxz:4.999.99:beta3
CWE    1
CWE-362
OVAL    2
oval:org.secpod.oval:def:118143
oval:org.secpod.oval:def:118139

© SecPod Technologies