USN-191-1: unzip vulnerability
30 September 2005
unzip vulnerability
Releases
Details
Imran Ghory found a race condition in the handling of output files.
While a file was unpacked by unzip, a local attacker with write
permissions to the target directory could exploit this to change the
permissions of arbitrary files of the unzip user.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.04
-
unzip
-
Ubuntu 4.10
-
unzip
-
In general, a standard system update will make all the necessary changes.