First published: Tue Sep 19 2006(Updated: )
Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
gzip | =1.3.5 |
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4337 has a high severity due to its ability to allow arbitrary code execution through a buffer overflow.
To fix CVE-2006-4337, upgrade to a version of gzip that is not vulnerable, specifically versions later than 1.3.5.
The affected software for CVE-2006-4337 is gzip version 1.3.5.
CVE-2006-4337 can be exploited by context-dependent attackers using crafted GZIP archives.
The impact of CVE-2006-4337 includes the potential execution of arbitrary code, which poses significant security risks.