CVE-2006-4334: Medium severity gzip gzip vulnerability

Published Sep 19, 2006
·
Updated

Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.

Other sources

Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.

Affected Software

3 affected componentsFixes available
redhat/gzip<0:1.3.3-13.rhel3
0:1.3.3-13.rhel3
redhat/gzip<0:1.3.3-16.rhel4
0:1.3.3-16.rhel4
gzip gzip=1.3.5

Event History

Sep 19, 2006
CVE Published
12:00 AM
Sep 20, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Aug 16, 2018
Data Sourced
12:35 PM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2006-4334?

CVE-2006-4334 has been classified as a denial of service vulnerability, allowing attackers to crash the gzip utility.

2

How do I fix CVE-2006-4334?

To address CVE-2006-4334, update gzip to version 1.3.3-13.rhel3 or 1.3.3-16.rhel4 or a later version.

3

What software is affected by CVE-2006-4334?

CVE-2006-4334 affects gzip version 1.3.5 and earlier versions in specific Red Hat distributions.

4

Can CVE-2006-4334 be exploited remotely?

Yes, CVE-2006-4334 can potentially be exploited by remote attackers through crafted GZIP archives.

5

What impact does CVE-2006-4334 have on system security?

The impact of CVE-2006-4334 is a denial of service, which could disrupt system operations when gzip is executed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203