PT-2010-1266 · Gnu · Gzip

Jan Lieskovsky

·

Publicado

2010-01-29

·

Atualizado

2024-06-15

·

CVE-2009-2624

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gzip versions prior to 1.3.13
Description The issue is related to the huft build function in inflate.c, which creates a hufts table that is too small. This allows remote attackers to cause a denial of service, such as an application crash or infinite loop, or possibly execute arbitrary code via a crafted archive.
Recommendations For versions prior to 1.3.13, update to version 1.3.13 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2624
DSA-1974-1
OPENSUSE-SU-2024:10059-1

Produtos afetados

Gzip