Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-4089
HistoryOct 29, 2011 - 12:00 a.m.

CVE-2011-4089

2011-10-2900:00:00
ubuntu.com
ubuntu.com
9

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

13.1%

The bzexe command in bzip2 1.0.5 and earlier generates compressed
executables that do not properly handle temporary files during extraction,
which allows local users to execute arbitrary code by precreating a
temporary directory.

Bugs

Notes

Author Note
tyhicks I don’t believe that YAMA prevents this vulnerability. It is not yet clear what versions are affected.
mdeslaur PoC: http://www.exploit-db.com/exploits/18147/ PoC: http://pastebin.com/FaaEsXRW
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchbzip2< 1.0.4-2ubuntu4.2UNKNOWN
ubuntu10.04noarchbzip2< 1.0.5-4ubuntu0.2UNKNOWN
ubuntu10.10noarchbzip2< 1.0.5-4ubuntu1.1UNKNOWN
ubuntu11.04noarchbzip2< 1.0.5-6ubuntu1.11.04.1UNKNOWN
ubuntu11.10noarchbzip2< 1.0.5-6ubuntu1.11.10.1UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

13.1%