CVE-2006-4337: Buffer Overflow
Published Sep 19, 2006
·Updated
Buffer overflow in the maketable function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.
Affected Software
1 affected component
gzip gzip=1.3.5
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Sep 19, 2006
CVE Published
09:07 PM
Sep 20, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4337?
CVE-2006-4337 has a high severity due to its ability to allow arbitrary code execution through a buffer overflow.
2
How do I fix CVE-2006-4337?
To fix CVE-2006-4337, upgrade to a version of gzip that is not vulnerable, specifically versions later than 1.3.5.
3
What software is affected by CVE-2006-4337?
The affected software for CVE-2006-4337 is gzip version 1.3.5.
4
Who can exploit CVE-2006-4337?
CVE-2006-4337 can be exploited by context-dependent attackers using crafted GZIP archives.
5
What is the impact of CVE-2006-4337?
The impact of CVE-2006-4337 includes the potential execution of arbitrary code, which poses significant security risks.