6.8
CVSSv2

CVE-2009-2624

Published: 29/01/2010 Updated: 18/11/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The huft_build function in inflate.c in gzip prior to 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote malicious users to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gzip 1.3.6

gnu gzip 1.3.5

gnu gzip

gnu gzip 1.3.10

gnu gzip 1.3

gnu gzip 1.3.2

gnu gzip 1.3.1

gnu gzip 1.3.9

gnu gzip 1.3.8

gnu gzip 1.3.7

gnu gzip 1.2.4

gnu gzip 1.2.4a

gnu gzip 1.3.11

gnu gzip 1.3.4

gnu gzip 1.3.3

Vendor Advisories

It was discovered that gzip incorrectly handled certain malformed compressed files If a user or automated system were tricked into opening a specially crafted gzip file, an attacker could cause gzip to crash or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-2624) ...
Several vulnerabilities have been found in gzip, the GNU compression utilities The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2624 Thiemo Nagel discovered a missing input sanitation flaw in the way gzip used to decompress data blocks for dynamic Huffman codes, which could lead to the execution of arbi ...