CVE-2022-1271

Source
https://cve.org/CVERecord?id=CVE-2022-1271
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1271.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1271
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (8)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (2)
openSUSE (3)
RHSA (14)
RLSA (4)
SUSE (10)
UBUNTU (1)
Related
Published
2022-08-31T15:33:00Z
Modified
2026-08-12T03:51:09Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-179"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1271.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "Fixed in gzip 1.12"
                },
                {
                    "last_affected":  "Fixed in gzip 1.12"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/tukaani-project/xz

Affected ranges

Type
GIT
Repo
https://github.com/tukaani-project/xz
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:tukaani:xz:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "5.2.5"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v4.*
v4.42.2alpha
v4.999.3alpha
v4.999.5alpha
v4.999.7beta
v4.999.8beta
v4.999.9beta
v5.*
v5.0.0
v5.1.0alpha
v5.1.1alpha
v5.1.2alpha
v5.1.3alpha
v5.1.4beta
v5.2.0
v5.2.1
v5.2.2
v5.2.3
v5.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1271.json"