|
|
| |
|
| |
gzip: arbitrary code execution
| Package(s): | gzip |
CVE #(s): | CVE-2010-0001
|
| Created: | January 20, 2010 |
Updated: | October 17, 2011 |
| Description: |
From the Red Hat advisory:
An integer underflow flaw, leading to an array index error, was found in
the way gzip expanded archive files compressed with the Lempel-Ziv-Welch
(LZW) compression algorithm. If a victim expanded a specially-crafted
archive, it could cause gzip to crash or, potentially, execute arbitrary
code with the privileges of the user running gzip. This flaw only affects
64-bit systems. (CVE-2010-0001) |
| Alerts: |
|
( Log in to post comments)
|
|
|