Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2006-1168

Опубликовано: 08 авг. 2006
Источник: redhat
CVSS2: 5.1

Описание

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

Отчет

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4busyboxNot affected
Red Hat Enterprise Linux 5ncompressNot affected
Red Hat Enterprise Linux 6ncompressNot affected
Red Hat Enterprise Linux 3ncompressFixedRHSA-2006:066312.09.2006
Red Hat Enterprise Linux 4ncompressFixedRHSA-2006:066312.09.2006
Red Hat Enterprise Linux 5busyboxFixedRHSA-2012:030821.02.2012
Red Hat Enterprise Linux 6busyboxFixedRHSA-2012:081019.06.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=201919ncompress: .bss buffer underflow in decompression

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 20 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

nvd
почти 20 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

debian
почти 20 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) ...

github
около 4 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

fstec
почти 20 лет назад

Уязвимость операционной системы Red Hat Enterprise Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

5.1 Medium

CVSS2