VDB
DEBIAN-CVE-2022-1271
DEBIAN-CVE-2022-1271
PUBLISHED
CVSS 8.800000190734863 HIGH
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | gzip | 1.10-4, 1.10-4, 0 |
| Debian:11 | xz-utils | 0, 0, 5.2.5-2 |
| Debian:12 | gzip | 0, 0, 0 |
| Debian:14 | xz-utils | 0, 0, 0 |
| Debian:12 | xz-utils | 0, 0, 0 |
| Debian:14 | gzip | 0, 0, 0 |
| Debian:13 | gzip | 0, 0, 0 |
| Debian:13 | xz-utils | 0, 0, 0 |
Exploit Intelligence
- Security issues CVE-2025-31115: Threaded .xz decoder frees memory too early CVE-2024-47611: Argument injection on Windows CVE-2024-3094: liblzma backdoor CVE-2022-1271: xzgrep filename handling CVE-2020-22916: A bogus CVE (github-poc-repo)
- Security issues CVE-2025-31115: Threaded .xz decoder frees memory too early CVE-2024-47611: Argument injection on Windows CVE-2024-3094: liblzma backdoor CVE-2022-1271: xzgrep filename handling CVE-2020-22916: A bogus CVE (github-poc)
- TestCommand.yaml (github-poc)
Timeline
- Aug 31, 2022 CVE Published
- Apr 28, 2026 CVE Updated