Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2006-1168

Опубликовано: 08 авг. 2006
Источник: redhat
CVSS2: 5.1

Описание

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

Отчет

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4busyboxNot affected
Red Hat Enterprise Linux 5ncompressNot affected
Red Hat Enterprise Linux 6ncompressNot affected
Red Hat Enterprise Linux 3ncompressFixedRHSA-2006:066312.09.2006
Red Hat Enterprise Linux 4ncompressFixedRHSA-2006:066312.09.2006
Red Hat Enterprise Linux 5busyboxFixedRHSA-2012:030821.02.2012
Red Hat Enterprise Linux 6busyboxFixedRHSA-2012:081019.06.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=201919ncompress: .bss buffer underflow in decompression

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 19 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

nvd
больше 19 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

debian
больше 19 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) ...

github
почти 4 года назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

fstec
больше 19 лет назад

Уязвимость операционной системы Red Hat Enterprise Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

5.1 Medium

CVSS2