Bug#321927: CAN-2005-2475: unzip TOCTOU file-permissions vulnerability

2005-08-08 Thread Santiago Vila
forwarded 321927 http://www.info-zip.org/zip-bug.html thanks I have just forwarded this report to the authors. Let's see what they have to say about it. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#321927: CAN-2005-2475: unzip TOCTOU file-permissions vulnerability

2005-08-08 Thread Moritz Muehlenhoff
Package: unzip Version: 5.52-3 Severity: normal Tags: security There has been a report about a minor security problem in unzip: If a malicious local user has write access to a directory in which a target user is using unzip to extract a file to then a TOCTOU bug can be exploited to change the