CVE-2006-4338: Medium severity gzip gzip vulnerability
Published Sep 19, 2006
·Updated
unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.
Affected Software
1 affected component
gzip gzip=1.3.5
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Sep 19, 2006
CVE Published
09:07 PM
Sep 20, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4338?
CVE-2006-4338 is categorized as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2006-4338?
To fix CVE-2006-4338, upgrade gzip to version 1.3.6 or later which addresses this vulnerability.
3
What impact does CVE-2006-4338 have?
CVE-2006-4338 allows attackers to create a crafted GZIP archive that can cause the application to enter an infinite loop, leading to service disruption.
4
Is my system affected by CVE-2006-4338?
If you are using gzip version 1.3.5, your system is affected by CVE-2006-4338.
5
Who is affected by CVE-2006-4338?
Any user or organization utilizing gzip version 1.3.5 is vulnerable to CVE-2006-4338.