CVE-2002-0760 Information
Feb 14, 2021
cve
Description
Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier OpenLinux 3.1 and 3.1.1 and possibly other operating systems decompresses files with world-readable permissions before setting the permissions to what is specified in the bzip2 archive which could allow local users to read the files as they are being decompressed.
Reference
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-039.0.txt ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:25.bzip2.asc http://www.iss.net/security_center/static/9127.php http://www.securityfocus.com/bid/4775
Share on: