CVE-2005-2475
Estado: ModificadaBaja (1.2)—
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N
- Puntuación base: 1.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt
- http://marc.info/?l=bugtraq&m=112300046224117&w=2
- http://secunia.com/advisories/16309
- http://secunia.com/advisories/16985
- http://secunia.com/advisories/17006
- http://secunia.com/advisories/17045
- http://secunia.com/advisories/17342
- http://secunia.com/advisories/17653
- http://secunia.com/advisories/25098
- http://securityreason.com/securityalert/32
- http://www.debian.org/security/2005/dsa-903
- http://www.info-zip.org/FAQ.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:197
- http://www.osvdb.org/18530
- http://www.redhat.com/support/errata/RHSA-2007-0203.html
- http://www.securityfocus.com/bid/14450
- http://www.trustix.org/errata/2005/0053/
- http://www.ubuntu.com/usn/usn-191-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9975
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt
- http://marc.info/?l=bugtraq&m=112300046224117&w=2
- http://secunia.com/advisories/16309
- http://secunia.com/advisories/16985
- http://secunia.com/advisories/17006
- http://secunia.com/advisories/17045
- http://secunia.com/advisories/17342
- http://secunia.com/advisories/17653
- http://secunia.com/advisories/25098
- http://securityreason.com/securityalert/32
- http://www.debian.org/security/2005/dsa-903
- http://www.info-zip.org/FAQ.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:197
- http://www.osvdb.org/18530
- http://www.redhat.com/support/errata/RHSA-2007-0203.html
- http://www.securityfocus.com/bid/14450
- http://www.trustix.org/errata/2005/0053/
- http://www.ubuntu.com/usn/usn-191-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9975
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-2475",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 1.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:H/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 1.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-08-05T04:00:00.000",
"references": [
{
"url": "ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=112300046224117&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/16309",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/16985",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/17006",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/17045",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/17342",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/17653",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25098",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/32",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2005/dsa-903",
"source": "cve@mitre.org"
},
{
"url": "http://www.info-zip.org/FAQ.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:197",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18530",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0203.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14450",
"source": "cve@mitre.org"
},
{
"url": "http://www.trustix.org/errata/2005/0053/",
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/usn-191-1",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9975",
"source": "cve@mitre.org"
},
{
"url": "ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=112300046224117&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/16309",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/16985",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/17006",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/17045",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/17342",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/17653",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25098",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/32",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2005/dsa-903",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.info-zip.org/FAQ.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:197",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18530",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0203.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/14450",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.trustix.org/errata/2005/0053/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/usn-191-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9975",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete."
},
{
"lang": "es",
"value": "Race condition en Unzip 5.52 permite que usuarios locales modifiquen permisos de ficheros arbitrarios mediante un ataque a un fichero que se esté descomprimiendo (cuyos permisos serán cambiados por Unzip después de que la descompresión se complete)."
}
],
"lastModified": "2026-06-16T22:14:57.817",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:info-zip:unzip:5.52:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6E12425-5797-46E1-AD6E-0F6616A36A50"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Red Hat is aware of this issue and is tracking it via the following bug:\nhttps://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=164927\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:\nhttp://www.redhat.com/security/updates/classification/\n\nRed Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.\n\nThe risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1 which is in maintenance mode.",
"lastModified": "2007-09-05T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}