Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35039
HistoryApr 10, 2022 - 10:33 a.m.

Remote Code Execution

2022-04-1010:33:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29
gzip
remote code execution
vulnerability
zgrep
xzgrep
arbitrary files

EPSS

0.012

Percentile

85.7%

Gzip is vulnerable to remote code execution. Insufficient validations when processing filenames with two or more newlines allow remote attackers to force zgrep or xzgrep to write arbitrary files on the system.