Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-15614

Опубликовано: 05 сент. 2026
Источник: debian

Описание

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ugrepfixed7.6.0+dfsg-1package

Примечания

  • https://github.com/Genivia/ugrep/issues/511

  • Fixed by: https://github.com/Genivia/ugrep/commit/c12849a11264e2c81c860bf78ee9039772f307a4 (v7.6.0)

  • Crash in CLI tool, no security impact

Связанные уязвимости

CVSS3: 3.3
ubuntu
8 дней назад

(ugrep before 7.6.0 contains a heap buffer over-read vulnerability in t ...)

CVSS3: 3.3
nvd
9 дней назад

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.

CVSS3: 3.3
github
9 дней назад

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.