CVE-2006-4336: High severity gzip gzip vulnerability
Published Sep 19, 2006
·Updated
Buffer underflow in the buildtree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.
Affected Software
1 affected component
gzip gzip=1.3.5
Remediation
Patch Available
Patch Available
Event History
Sep 19, 2006
CVE Published
09:07 PM
Sep 20, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4336?
CVE-2006-4336 has a high severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2006-4336?
To fix CVE-2006-4336, upgrade to a patched version of gzip that is not affected by this vulnerability.
3
Which versions of gzip are affected by CVE-2006-4336?
CVE-2006-4336 specifically affects gzip version 1.3.5.
4
Who can exploit CVE-2006-4336?
CVE-2006-4336 can be exploited by context-dependent attackers who can provide a crafted leaf count table.
5
What type of vulnerability is CVE-2006-4336 classified as?
CVE-2006-4336 is classified as a buffer underflow vulnerability.