Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54476
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-159-1 (unzip)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to unzip
announced via advisory USN-159-1.

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)

The following packages are affected: unzip

If a ZIP archive contains binaries with the setuid and/or setgid bit
set, unzip preserved those bits when extracting the archive. This
could be exploited by tricking the administrator into unzipping an
archive with a setuid-root binary into a directory the attacker can
access. This allowed the attacker to execute arbitrary commands with
root privileges.

The updated version does not preserve setuid, setgid, and sticky bits
any more by default. The old behaviour can be explicitly requested now
by supplying the option '-K'.

Solution:
The problem can be corrected by upgrading the affected package to
version 5.51-2ubuntu0.1 (for Ubuntu 4.10), or 5.51-2ubuntu1.1 (for
Ubuntu 5.04). In general, a standard system upgrade is sufficient to
effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-159-1

Risk factor : High

CVSS Score:
6.2

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0602
BugTraq ID: 14447
http://www.securityfocus.com/bid/14447
Bugtraq: 20050228 7a69Adv#22 - UNIX unzip keep setuid and setgid files (Google Search)
http://marc.info/?l=bugtraq&m=110960796331943&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2005:197
http://secunia.com/advisories/17045
http://secunia.com/advisories/17342
http://secunia.com/advisories/27684
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103150-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200844-1
http://www.trustix.org/errata/2005/0053/
http://www.vupen.com/english/advisories/2007/3866
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.