Description
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
Published: 2005-05-13
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2005-0759 zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
Ubuntu USN Ubuntu USN USN-158-1 gzip utility vulnerability
Ubuntu USN Ubuntu USN USN-161-1 bzip2 utility vulnerability
References
Link Providers
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt cve-icon cve-icon
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc cve-icon cve-icon
http://bugs.gentoo.org/show_bug.cgi?id=90626 cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=306172 cve-icon cve-icon
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2005-357.html cve-icon cve-icon
http://secunia.com/advisories/18100 cve-icon cve-icon
http://secunia.com/advisories/19183 cve-icon cve-icon
http://secunia.com/advisories/22033 cve-icon cve-icon
http://secunia.com/advisories/26235 cve-icon cve-icon
http://securitytracker.com/id?1013928 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852 cve-icon cve-icon
http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200505-05.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:026 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:027 cve-icon cve-icon
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html cve-icon cve-icon
http://www.osvdb.org/16371 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2005-474.html cve-icon cve-icon
http://www.securityfocus.com/bid/13582 cve-icon cve-icon
http://www.securityfocus.com/bid/25159 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-158-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/2732 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/20539 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2005-0758 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1081 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1107 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9797 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2005-0758 cve-icon
History

No history.

Subscriptions

Canonical Ubuntu Linux
Gnu Gzip
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T21:28:27.167Z

Reserved: 2005-03-17T00:00:00.000Z

Link: CVE-2005-0758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-05-13T04:00:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2005-0758

cve-icon Redhat

Severity : Low

Publid Date: 2005-04-22T00:00:00Z

Links: CVE-2005-0758 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses