CVE Vulnerabilities

CVE-2006-4335

Published: Sep 19, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a stack modification vulnerability.

Affected Software

Name Vendor Start Version End Version
Gzip Gzip 1.3.5 (including) 1.3.5 (including)
Red Hat Enterprise Linux 3 RedHat gzip-0:1.3.3-13.rhel3 *
Red Hat Enterprise Linux 4 RedHat gzip-0:1.3.3-16.rhel4 *
Gzip Ubuntu dapper *
Gzip Ubuntu devel *
Gzip Ubuntu edgy *
Gzip Ubuntu feisty *
Gzip Ubuntu gutsy *
Gzip Ubuntu hardy *
Gzip Ubuntu intrepid *
Gzip Ubuntu jaunty *
Gzip Ubuntu karmic *
Lha Ubuntu dapper *
Lha Ubuntu devel *
Lha Ubuntu edgy *
Lha Ubuntu feisty *
Lha Ubuntu gutsy *
Lha Ubuntu hardy *
Lha Ubuntu intrepid *
Lha Ubuntu jaunty *
Lha Ubuntu karmic *

References