Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2006-1168
Disclosure Date: August 14, 2006 (last updated October 04, 2023)
The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.
0
Attacker Value
Unknown
CVE-2005-2991
Disclosure Date: September 20, 2005 (last updated February 22, 2025)
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
0
Attacker Value
Unknown
CVE-2001-1413
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
0