4.6

CVE-2005-0758

zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

Data is provided by the National Vulnerability Database (NVD)
GnuGzip Version < 1.3.5
CanonicalUbuntu Linux Version4.10
CanonicalUbuntu Linux Version5.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.321
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
http://www.securityfocus.com/bid/25159
Third Party Advisory
VDB Entry
http://securitytracker.com/id?1013928
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/13582
Third Party Advisory
VDB Entry