Vulnerability CVE-2022-1271: Information

Description

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: Aug. 31, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-20

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
gzipsisyphus1.12-alt11.13-alt2ALT-PU-2022-1660-1298174Fixed
gzipsisyphus_e2k1.12-alt1.11.13-alt2ALT-PU-2022-4705-1-Fixed
gzipsisyphus_mipsel1.12-alt11.12-alt1ALT-PU-2022-4542-1-Fixed
gzipsisyphus_riscv641.12-alt11.13-alt2ALT-PU-2022-4545-1-Fixed
gzipp101.12-alt11.12-alt1ALT-PU-2022-1667-1298175Fixed
gzipp10_e2k1.12-alt1.11.12-alt1.1ALT-PU-2022-4591-1-Fixed
gzipp91.10-alt1.p9.11.10-alt1.p9.1ALT-PU-2023-1597-1316771Fixed
gzipp9_e2k1.10-alt1.p9.11.10-alt1.p9.1ALT-PU-2023-5369-1-Fixed
gzipc10f11.12-alt11.12-alt1ALT-PU-2022-1667-1298175Fixed
gzipc9f21.10-alt1.p9.11.10-alt1.p9.1ALT-PU-2023-1595-1318022Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*
      End excliding
      1.12

      Configuration 2

      cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*