CVE-2013-0296

Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zlib:pigz:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-04-27 21:55

Updated : 2023-12-10 11:31


NVD link : CVE-2013-0296

Mitre link : CVE-2013-0296

CVE.ORG link : CVE-2013-0296


JSON object : View

Products Affected

zlib

  • pigz
CWE
CWE-264

Permissions, Privileges, and Access Controls