4.6

CVE-2011-4089

Exploit

The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

Data is provided by the National Vulnerability Database (NVD)
BzipBzip2 Version <= 1.0.4
BzipBzip2 Version1.0
BzipBzip2 Version1.0.1
BzipBzip2 Version1.0.2
BzipBzip2 Version1.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.379
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P