Back

MEDIUM

gzip: Missing input sanitation by decompressing dynamic Huffman code blocks

Published Jan 29, 2010

Description

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of gzip as shipped with Red Hat Enterprise Linux 3, 4, or 5. It was corrected in the versions of gzip as shipped with Red Hat Enterprise Linux 6.0 and later.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Jan 29, 2010
Updated Aug 7, 2024
Reserved Jul 28, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jan 20, 2010