Back

CVE-2004-0603

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.

Published: Dec 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
gnu gzip *

GitHub Security Advisory GHSA-px52-rq5c-w9gw

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 3.13%

Top 13% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub