Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2624

Опубликовано: 20 янв. 2010
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

Отчет

Not vulnerable. This issue did not affect the versions of gzip as shipped with Red Hat Enterprise Linux 3, 4, or 5. It was corrected in the versions of gzip as shipped with Red Hat Enterprise Linux 6.0 and later.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=514711gzip: Missing input sanitation by decompressing dynamic Huffman code blocks

EPSS

Процентиль: 91%
0.07318
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

nvd
около 16 лет назад

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

debian
около 16 лет назад

The huft_build function in inflate.c in gzip before 1.3.13 creates a h ...

github
почти 4 года назад

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

EPSS

Процентиль: 91%
0.07318
Низкий

6.8 Medium

CVSS2