The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
2014-04-16T18:37:11.257
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bzip | bzip2 | ≤ 1.0.4 | Yes |
Application | bzip | bzip2 | 1.0 | Yes |
Application | bzip | bzip2 | 1.0.1 | Yes |
Application | bzip | bzip2 | 1.0.2 | Yes |
Application | bzip | bzip2 | 1.0.3 | Yes |