Bug 156269 - CAN-2005-1228 directory traversal bug
CAN-2005-1228 directory traversal bug
Product: Fedora
Classification: Fedora
Component: gzip (Show other bugs)
All Linux
medium Severity low
: ---
: ---
Assigned To: Ivana Varekova
Ben Levenson
: Security
Depends On:
  Show dependency treegraph
Reported: 2005-04-28 11:47 EDT by Josh Bressers
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-05-03 06:11:28 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Used patch. (517 bytes, patch)
2005-04-29 09:47 EDT, Ivana Varekova
no flags Details | Diff

  None (edit)
Description Josh Bressers 2005-04-28 11:47:00 EDT
+++ This bug was initially created as a clone of Bug #156266 +++

A directory traversal bug exists in multiple versions of gzip. When
compressing a file, gzip saves its original name but not its path inside
the compressed file. When using gunzip's "-N" option, the original name
found inside the compressed file will be used as the name to save the
decompressed file with. "gunzip -N" doesn't check if the original name inside
the compressed file has any "/" characters in it. This makes it possible to
create a malicious compressed file that when decompressed with "gunzip -N"
will create a file at an arbitrary location in the file system.

Comment 1 Ivana Varekova 2005-04-29 09:47:44 EDT
Created attachment 113840 [details]
Used patch.

I used Ulf Harnhammar.
I fixed this problem in devel (gzip-1.3.5-5). 
(Gunzip remove any directory prefix if you use -N and in compressed input file
contain name with "/" characters.)

Ivana Varekova

Note You need to log in before you can comment on or make changes to this bug.