← Back to CVEs
CVE-2013-0296
N/ADescription
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.
CVE Details
CVSS v3.1 ScoreN/A
Published4/27/2014
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0
Affected Products
zlib:pigz
Weaknesses (CWE)
CWE-264
References
http://lists.opensuse.org/opensuse-updates/2013-03/msg00106.html(secalert@redhat.com)
http://mail.zlib.net/pipermail/pigz-announce_zlib.net/2012-July/000006.html(secalert@redhat.com)
http://www.openwall.com/lists/oss-security/2013/02/15/4(secalert@redhat.com)
http://www.openwall.com/lists/oss-security/2013/02/16/3(secalert@redhat.com)
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700608(secalert@redhat.com)
http://lists.opensuse.org/opensuse-updates/2013-03/msg00106.html(af854a3a-2127-422b-91ae-364da2661108)
http://mail.zlib.net/pipermail/pigz-announce_zlib.net/2012-July/000006.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2013/02/15/4(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2013/02/16/3(af854a3a-2127-422b-91ae-364da2661108)
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700608(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.