5

CVE-2002-0759

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the user if an existing file would be overwritten, which could allow attackers to overwrite files via a bzip2 archive.

Data is provided by the National Vulnerability Database (NVD)
BzipBzip2 Version0.9.0
BzipBzip2 Version0.9.0a
BzipBzip2 Version0.9.0b
BzipBzip2 Version0.9.0c
BzipBzip2 Version0.9.5a
BzipBzip2 Version0.9.5b
BzipBzip2 Version0.9.5c
BzipBzip2 Version0.9.5d
BzipBzip2 Version1.0
BzipBzip2 Version1.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.83% 0.736
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N