PT-2010-1266 · Gnu · Gzip

Jan Lieskovsky

·

Published

2010-01-29

·

Updated

2024-06-15

·

CVE-2009-2624

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gzip versions prior to 1.3.13
Description The issue is related to the huft build function in inflate.c, which creates a hufts table that is too small. This allows remote attackers to cause a denial of service, such as an application crash or infinite loop, or possibly execute arbitrary code via a crafted archive.
Recommendations For versions prior to 1.3.13, update to version 1.3.13 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2624
DSA-1974-1
OPENSUSE-SU-2024:10059-1

Affected Products

Gzip