CVE-2005-0953

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

Published: 2005-05-02 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2005-0953 is rated Low Risk (23/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.09%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2005-0953

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.35% 0.09% -0.26%
2 2024-12-17 0.06% 0.35% +0.29%
3 2023-03-07 0.06%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2005-0953

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.7 2.0 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
1.9 6.4 [email protected]

Weakness enumeration for CVE-2005-0953

OS Trackers for CVE-2005-0953

vendor priority summary link
debian not yet assigned CVE-2005-0953 not yet assigned priority: Debian including 1 source packages (bzip2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2005-0953
redhat low https://access.redhat.com/security/cve/CVE-2005-0953
ubuntu medium CVE-2005-0953 medium priority: Ubuntu including 1 source packages (bzip2), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 3, needs-triage 1. https://ubuntu.com/security/CVE-2005-0953

Vendor comments (NVD) for CVE-2005-0953

  • Red Hat (2007-03-14T00:00:00)

    Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Affected software / configurations for CVE-2005-0953

Vendor Product Version Raw CPE
bzip bzip2 0.9 cpe:2.3:a:bzip:bzip2:0.9:*:*:*:*:*:*:*
bzip bzip2 0.9.5_a cpe:2.3:a:bzip:bzip2:0.9.5_a:*:*:*:*:*:*:*
bzip bzip2 0.9.5_b cpe:2.3:a:bzip:bzip2:0.9.5_b:*:*:*:*:*:*:*
bzip bzip2 0.9.5_c cpe:2.3:a:bzip:bzip2:0.9.5_c:*:*:*:*:*:*:*
bzip bzip2 0.9.5_d cpe:2.3:a:bzip:bzip2:0.9.5_d:*:*:*:*:*:*:*
bzip bzip2 0.9_a cpe:2.3:a:bzip:bzip2:0.9_a:*:*:*:*:*:*:*
bzip bzip2 0.9_b cpe:2.3:a:bzip:bzip2:0.9_b:*:*:*:*:*:*:*
bzip bzip2 0.9_c cpe:2.3:a:bzip:bzip2:0.9_c:*:*:*:*:*:*:*
bzip bzip2 1.0 cpe:2.3:a:bzip:bzip2:1.0:*:*:*:*:*:*:*
bzip bzip2 1.0.1 cpe:2.3:a:bzip:bzip2:1.0.1:*:*:*:*:*:*:*
bzip bzip2 1.0.2 cpe:2.3:a:bzip:bzip2:1.0.2:*:*:*:*:*:*:*

References for CVE-2005-0953

URL Tags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc
http://docs.info.apple.com/article.html?artnum=307041
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
http://marc.info/?l=bugtraq&m=111229375217633&w=2
http://secunia.com/advisories/19183
http://secunia.com/advisories/27274
http://secunia.com/advisories/27643
http://secunia.com/advisories/29940
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103118-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200191-1
http://www.debian.org/security/2005/dsa-730 Patch Vendor Advisory
http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:026
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html
http://www.redhat.com/support/errata/RHSA-2005-474.html
http://www.securityfocus.com/archive/1/456430/30/8730/threaded
http://www.securityfocus.com/bid/12954
http://www.securityfocus.com/bid/26444
http://www.us-cert.gov/cas/techalerts/TA07-319A.html US Government Resource
http://www.vupen.com/english/advisories/2007/3525
http://www.vupen.com/english/advisories/2007/3868
https://exchange.xforce.ibmcloud.com/vulnerabilities/19926
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10902
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1154
cvelogic Threat Intelligence