The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2010-01-29T18:00:00
Updated: 2024-08-07T05:59:56.266Z
Reserved: 2009-07-28T00:00:00
Link: CVE-2009-2624
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-01-29T18:30:00.793
Modified: 2024-11-21T01:05:19.247
Link: CVE-2009-2624
Redhat