Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2022-1271
Disclosure Date: August 31, 2022 (last updated August 26, 2024)
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2009-2624
Disclosure Date: January 29, 2010 (last updated October 04, 2023)
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
0
Attacker Value
Unknown
CVE-2010-0001
Disclosure Date: January 29, 2010 (last updated October 04, 2023)
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
0
Attacker Value
Unknown
CVE-2006-4336
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.
0
Attacker Value
Unknown
CVE-2006-4338
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.
0
Attacker Value
Unknown
CVE-2006-4337
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.
0
Attacker Value
Unknown
CVE-2006-4335
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."
0
Attacker Value
Unknown
CVE-2006-4334
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.
0
Attacker Value
Unknown
CVE-2006-1715
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Christian Kindahl TUGZip 3.4.0.0, 3.3.0.0, and 3.1.0.2 allow user-assisted attackers to create files in arbitrary directories via a .. (dot dot) in an archive pack with a crafted (1) .gz, (2) .jar, (3) .rar, or (4) .zip file.
0
Attacker Value
Unknown
CVE-2005-4594
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in TUGZip 3.4.0.0 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.
0