First published: Tue Sep 19 2006(Updated: )
Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
gzip | =1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4336 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2006-4336, upgrade to a patched version of gzip that is not affected by this vulnerability.
CVE-2006-4336 specifically affects gzip version 1.3.5.
CVE-2006-4336 can be exploited by context-dependent attackers who can provide a crafted leaf count table.
CVE-2006-4336 is classified as a buffer underflow vulnerability.