It was reported [1] that pxz sets the mode of an output file to be the same as the one of an input file but does it only after compression is over. This leaves the output file with the wrong mode during all the time of the compression process. Illustration: $ truncate -s 1G foo $ chmod 600 foo $ pxz foo & [1] 9240 $ ls -l foo.xz -rw-r--r-- 1 user user 0 Jan 14 00:33 foo.xz $ wait % [1]+ Done pxz foo $ ls -l foo.xz -rw------- 1 user user 161976 Jan 14 00:33 foo.xz The issue is similar to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0296 [1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775306
Created pxz tracking bugs for this issue: Affects: fedora-all [bug 1182025] Affects: epel-6 [bug 1182026]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.