CVE-2004-1349

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
04/10/2004
Last modified:
03/04/2025

Description

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:* 1.3 (excluding)
cpe:2.3:o:oracle:solaris:8:*:*:*:*:*:*:*