CVE-2006-4334: Medium severity gzip gzip vulnerability
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Other sources
Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4334?
CVE-2006-4334 has been classified as a denial of service vulnerability, allowing attackers to crash the gzip utility.
How do I fix CVE-2006-4334?
To address CVE-2006-4334, update gzip to version 1.3.3-13.rhel3 or 1.3.3-16.rhel4 or a later version.
What software is affected by CVE-2006-4334?
CVE-2006-4334 affects gzip version 1.3.5 and earlier versions in specific Red Hat distributions.
Can CVE-2006-4334 be exploited remotely?
Yes, CVE-2006-4334 can potentially be exploited by remote attackers through crafted GZIP archives.
What impact does CVE-2006-4334 have on system security?
The impact of CVE-2006-4334 is a denial of service, which could disrupt system operations when gzip is executed.