CVE-2011-4089
Published Apr 16, 2014
·Updated
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
Affected Software
5 affected components
Bzip bzip2=1.0
Bzip bzip2<=1.0.4
Bzip bzip2=1.0.3
Bzip bzip2=1.0.2
Bzip bzip2=1.0.1
Remediation
Patch Available
Patch Available
Event History
Apr 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:37 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4089?
CVE-2011-4089 is considered a high severity vulnerability due to the potential for local users to execute arbitrary code.
2
How do I fix CVE-2011-4089?
To fix CVE-2011-4089, users should upgrade to bzip2 version 1.0.5 or later.
3
What versions of bzip2 are affected by CVE-2011-4089?
CVE-2011-4089 affects bzip2 versions up to 1.0.4 and including versions 1.0, 1.0.1, 1.0.2, and 1.0.3.
4
Can CVE-2011-4089 be exploited remotely?
CVE-2011-4089 cannot be exploited remotely as it requires local access to the system.
5
What is the nature of the vulnerability in CVE-2011-4089?
CVE-2011-4089 involves improper handling of temporary files during extraction by the bzexe command.