Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2009-2624

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
0
Attacker Value
Unknown

CVE-2010-0001

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
0
Attacker Value
Unknown

CVE-2006-4336

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.
0
Attacker Value
Unknown

CVE-2006-4338

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.
0
Attacker Value
Unknown

CVE-2006-4337

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.
0
Attacker Value
Unknown

CVE-2006-4335

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."
0
Attacker Value
Unknown

CVE-2006-4334

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.
0
Attacker Value
Unknown

CVE-2005-1228

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
0
Attacker Value
Unknown

CVE-2005-0988

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
0
Attacker Value
Unknown

CVE-2003-0842

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.
0