Description
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-4040 | The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory. |
Ubuntu USN |
USN-1308-1 | bzip2 vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T23:53:32.623Z
Reserved: 2011-10-18T00:00:00.000Z
Link: CVE-2011-4089
No data.
Status : Deferred
Published: 2014-04-16T18:37:11.257
Modified: 2025-04-12T10:46:40.837
Link: CVE-2011-4089
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN