CVE-2015-1191
Published Jan 21, 2015Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
Vendor/product archive
2 CVEs tagged to zlib / pigz — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, whi…