Lucene search

K
osvGoogleOSV:USN-5378-1
HistoryApr 13, 2022 - 12:37 p.m.

gzip vulnerability

2022-04-1312:37:06
Google
osv.dev
7
gzip
vulnerability
file overwrite

AI Score

7.4

Confidence

Low

EPSS

0.012

Percentile

85.7%

Cleemy Desu Wayo discovered that Gzip incorrectly handled certain
filenames. If a user or automated system were tricked into performing zgrep
operations with specially crafted filenames, a remote attacker could
overwrite arbitrary files.