SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#596848

gzip contains an infinite loop vulnerability in its LZH handling

Overview

The gzip program contains a infinite loop vulnerability that may allow an attacker to create a denial-of-service condition.

I. Description

The gzip program is used to compress and decompress archived files.

A infinite loop vulnerability exists in the way gzip handles certain files. An attacker may be able to exploit this vulnerability by convincing a user to open a specially crafted gzip file.

Note that the attacker could either convince a user to open a malicious gzip file, or save the file in a place where another program would call gzip to decompress the archive.

II. Impact

A remote, unauthenticated attacker may be able to create a denial-of-service condition.

III. Solution

Upgrade

This issue has been addressed in gzip 1.3.6. See the systems affected section of this document for information about specific vendors.

Workarounds
Until updates can be applied, the following workarounds may mitigate the impact of this vulnerability:

  • Do not decompress gzip files that are received from unknown sources.
  • Do not execute gzip with system-level privileges.
  • Some automated processes may rely on gzip to complete their tasks. When possible, disable such programs or do not allow them to execute gzip with root privileges.

Systems Affected

VendorStatusDate Updated
3com, Inc.Unknown19-Sep-2006
Aladdin Knowledge SystemsUnknown19-Sep-2006
AlcatelUnknown19-Sep-2006
Apple Computer, Inc.Vulnerable5-Dec-2006
AT&TUnknown19-Sep-2006
Avaya, Inc.Unknown19-Sep-2006
Avici Systems, Inc.Unknown19-Sep-2006
Borderware TechnologiesUnknown19-Sep-2006
Charlotte's Web NetworksUnknown19-Sep-2006
Check Point Software TechnologiesUnknown19-Sep-2006
Chiaro Networks, Inc.Unknown19-Sep-2006
Cisco Systems, Inc.Unknown19-Sep-2006
ClavisterUnknown19-Sep-2006
Command Software SystemsUnknown19-Sep-2006
Computer AssociatesNot Vulnerable27-Jul-2007
Conectiva Inc.Unknown19-Sep-2006
Cray Inc.Unknown19-Sep-2006
CyberSoft, Inc.Unknown19-Sep-2006
D-Link Systems, Inc.Unknown19-Sep-2006
Data Connection, Ltd.Unknown19-Sep-2006
DataFellowsUnknown19-Sep-2006
Debian GNU/LinuxVulnerable4-Oct-2006
Debian GNU/LinuxUnknown19-Sep-2006
EMC, Inc. (formerly Data General Corporation)Unknown19-Sep-2006
Engarde Secure LinuxUnknown19-Sep-2006
EricssonUnknown19-Sep-2006
eSoft, Inc.Unknown19-Sep-2006
Extreme NetworksUnknown19-Sep-2006
F-PROT by FRISK Software InternationalUnknown19-Sep-2006
F-Secure CorporationUnknown19-Sep-2006
F5 Networks, Inc.Unknown19-Sep-2006
Fedora ProjectUnknown19-Sep-2006
Finjan SoftwareUnknown19-Sep-2006
Force10 Networks, Inc.Unknown19-Sep-2006
Fortinet, Inc.Unknown19-Sep-2006
Foundry Networks, Inc.Unknown19-Sep-2006
FreeBSD, Inc.Vulnerable29-Sep-2006
FujitsuUnknown7-Mar-2007
Gentoo LinuxUnknown19-Sep-2006
GFI Software, Inc.Unknown19-Sep-2006
Global Technology AssociatesNot Vulnerable20-Sep-2006
Hewlett-Packard CompanyUnknown19-Sep-2006
HitachiNot Vulnerable20-Sep-2006
HyperchipUnknown19-Sep-2006
IBM CorporationUnknown19-Sep-2006
IBM Corporation (zseries)Unknown19-Sep-2006
IBM eServerUnknown19-Sep-2006
Immunix Communications, Inc.Unknown19-Sep-2006
Ingrian Networks, Inc.Unknown19-Sep-2006
Intel CorporationUnknown19-Sep-2006
Internet Security Systems, Inc.Unknown19-Sep-2006
IntotoNot Vulnerable20-Sep-2006
IP FilterUnknown19-Sep-2006
Juniper Networks, Inc.Unknown19-Sep-2006
Linksys (A division of Cisco Systems)Unknown19-Sep-2006
Lucent TechnologiesUnknown19-Sep-2006
Luminous NetworksUnknown19-Sep-2006
Mandriva, Inc.Unknown19-Sep-2006
MessageLabsUnknown19-Sep-2006
Microsoft CorporationUnknown19-Sep-2006
MontaVista Software, Inc.Unknown19-Sep-2006
Multinet (owned Process Software Corporation)Unknown19-Sep-2006
Multitech, Inc.Unknown19-Sep-2006
NEC CorporationUnknown19-Sep-2006
NetBSDUnknown19-Sep-2006
netfilterUnknown19-Sep-2006
Network Appliance, Inc.Unknown19-Sep-2006
NextHop Technologies, Inc.Unknown19-Sep-2006
NokiaUnknown19-Sep-2006
Nortel Networks, Inc.Unknown19-Sep-2006
Novell, Inc.Unknown19-Sep-2006
OpenBSDUnknown19-Sep-2006
Openwall GNU/*/LinuxVulnerable20-Sep-2006
Proland Software, Inc.Unknown19-Sep-2006
QNX, Software Systems, Inc.Unknown19-Sep-2006
Red Hat, Inc.Vulnerable20-Sep-2006
Redback Networks, Inc.Unknown19-Sep-2006
Riverstone Networks, Inc.Unknown19-Sep-2006
Secure Computing Network Security DivisionUnknown19-Sep-2006
Secureworx, Inc.Unknown19-Sep-2006
Silicon Graphics, Inc.Unknown19-Sep-2006
Slackware Linux Inc.Vulnerable25-Sep-2006
Sony CorporationUnknown19-Sep-2006
Sophos, Inc.Unknown19-Sep-2006
StonesoftUnknown19-Sep-2006
Sun Microsystems, Inc.Unknown19-Sep-2006
SUSE LinuxUnknown19-Sep-2006
Symantec, Inc.Unknown19-Sep-2006
The SCO GroupUnknown19-Sep-2006
TrendmicroUnknown19-Sep-2006
Trustix Secure LinuxUnknown19-Sep-2006
TurbolinuxUnknown19-Sep-2006
UbuntuVulnerable22-Sep-2006
UnisysUnknown19-Sep-2006
Watchguard Technologies, Inc.Unknown19-Sep-2006
Wind River Systems, Inc.Unknown19-Sep-2006
ZyXELUnknown19-Sep-2006

References


http://www.gzip.org/
http://www.auscert.org.au/7179

Credit

Thanks to Tavis Ormandy, Google Security Team for reporting this issue.

This document was written by Ryan Giobbi.

Other Information

Date Public06/19/2006
Date First Published09/19/2006 04:42:35 PM
Date Last Updated07/27/2007
CERT Advisory 
CVE-ID(s)CVE-2006-4338
NVD-ID(s)CVE-2006-4338
US-CERT Technical Alerts 
Metric0.31
Document Revision37

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader