HomeGnuCVE-2022-1271

CVE-2022-1271

HIGH
8.8CVSS
Published: 2022-08-31
Updated: 2025-06-09
AI Analysis

Description

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-179CWE-20

Metadata

Primary Vendor
GNU
Published
8/31/2022
Last Modified
6/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

gnu : gzipredhat : jboss_data_griddebian : debian_linuxtukaani : xz

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-1271 | HIGH Severity | CVEDatabase.com | CVEDatabase.com