gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17577 | vdb entry third party advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57600-1&searchclause=security | broken link patch vendor advisory |
http://www.kb.cert.org/vuls/id/635998 | third party advisory us government resource |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1654 | vdb entry not applicable signature |
http://www.securityfocus.com/bid/11318 | patch vendor advisory vdb entry third party advisory broken link |
http://secunia.com/advisories/12744 | not applicable third party advisory patch vendor advisory |