Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 9 | all | pxz | < 4.999.99~beta5+gitfcfea93-1 | pxz_4.999.99~beta5+gitfcfea93-1_all.deb |