[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1974 gzip -- several vulnerabilities

ID: oval:org.mitre.oval:def:7495Date: (C)2010-05-24   (M)2024-05-22
Class: PATCHFamily: unix




Several vulnerabilities have been found in gzip, the GNU compression utilities. The Common Vulnerabilities and Exposures project identifies the following problems: Thiemo Nagel discovered a missing input sanitation flaw in the way gzip used to decompress data blocks for dynamic Huffman codes, which could lead to the execution of arbitrary code when trying to decompress a crafted archive. This issue is a reappearance of CVE-2006-4334 and only affects the lenny version. Aki Helin discovered an integer underflow when decompressing files that are compressed using the LZW algorithm. This could lead to the execution of arbitrary code when trying to decompress a crafted LZW compressed gzip archive.

Platform:
Debian 5.0
Debian 4.0
Product:
gzip
Reference:
DSA-1974
CVE-2009-2624
CVE-2010-0001
CVE-2006-4334
CVE    3
CVE-2006-4334
CVE-2009-2624
CVE-2010-0001
CPE    2
cpe:/o:debian:debian_linux:4.x
cpe:/o:debian:debian_linux:5.x

© SecPod Technologies