Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Bzip2 | — | Upgrade macOS to the latest version | Dec 16, 2011 | May 2, 2005 |
| Debian | — | Upgrade bzip2 | Jul 30, 2024 | May 2, 2005 |
| Freebsd | — | Upgrade FreeBSDUpgrade bzip2 | Dec 10, 2025 | Jun 29, 2005 |
| Ubuntu | — | Upgrade bzip2 | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub