Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2022-1271

Disclosure Date: August 31, 2022 (last updated August 26, 2024)
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Attacker Value
Unknown

CVE-2009-2624

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
0
Attacker Value
Unknown

CVE-2010-0001

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
0
Attacker Value
Unknown

CVE-2006-4336

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.
0
Attacker Value
Unknown

CVE-2006-4338

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.
0
Attacker Value
Unknown

CVE-2006-4337

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.
0
Attacker Value
Unknown

CVE-2006-4335

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."
0
Attacker Value
Unknown

CVE-2006-4334

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.
0
Attacker Value
Unknown

CVE-2006-1715

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Christian Kindahl TUGZip 3.4.0.0, 3.3.0.0, and 3.1.0.2 allow user-assisted attackers to create files in arbitrary directories via a .. (dot dot) in an archive pack with a crafted (1) .gz, (2) .jar, (3) .rar, or (4) .zip file.
0
Attacker Value
Unknown

CVE-2005-4594

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in TUGZip 3.4.0.0 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.
0