Vulnerability Note VU#381508
gzip contains an array out-of-bounds vulnerability in make_table()
Overview
The gzip program contains a stack modification vulnerability that may allow an attacker to execute arbitrary code, or create a denial-of-service condition..
Description
The gzip program is used to compress and decompress archived files. A stack modification vulnerability exists in gzip. An attacker may be able to exploit this vulnerability by convincing a user to open a specially crafted gzip file. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code, or create a denial-of-service condition.. |
Solution
Upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Apple Computer, Inc. | Affected | 08 Sep 2006 | 05 Dec 2006 |
| Debian GNU/Linux | Affected | - | 04 Oct 2006 |
| FreeBSD, Inc. | Affected | 08 Sep 2006 | 29 Sep 2006 |
| Openwall GNU/*/Linux | Affected | 08 Sep 2006 | 20 Sep 2006 |
| Red Hat, Inc. | Affected | 08 Sep 2006 | 20 Sep 2006 |
| Slackware Linux Inc. | Affected | 08 Sep 2006 | 25 Sep 2006 |
| Ubuntu | Affected | 08 Sep 2006 | 22 Sep 2006 |
| Computer Associates | Not Affected | 08 Sep 2006 | 27 Jul 2007 |
| Force10 Networks, Inc. | Not Affected | 08 Sep 2006 | 22 Jul 2011 |
| Global Technology Associates | Not Affected | 08 Sep 2006 | 18 Sep 2006 |
| Hitachi | Not Affected | 08 Sep 2006 | 20 Sep 2006 |
| 3com, Inc. | Unknown | 08 Sep 2006 | 08 Sep 2006 |
| Aladdin Knowledge Systems | Unknown | 08 Sep 2006 | 08 Sep 2006 |
| Alcatel | Unknown | 08 Sep 2006 | 08 Sep 2006 |
| AT&T | Unknown | 08 Sep 2006 | 08 Sep 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
Credit
Thanks to Tavis Ormandy, Google Security Team for reporting this issue.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2006-4335
- Date Public: 19 Jun 2006
- Date First Published: 19 Sep 2006
- Date Last Updated: 22 Jul 2011
- Severity Metric: 1.57
- Document Revision: 55
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.