Back

CVE-2005-1228

Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
gnu gzip 1.2.4
gnu gzip 1.3.3

GitHub Security Advisory GHSA-9855-w374-4v24

Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 3.58%

Top 12% most likely to be exploited

Threat Score 21.1 / 100

Data Sources

NVD EPSS GitHub