Denial of Service Vulnerability in Gzip by GNU
CVE-2009-2624

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
29 January 2010

Summary

The huft_build function in inflate.c of Gzip versions prior to 1.3.13 has a flaw that leads to the creation of an inadequately sized Huffman table. This vulnerability can be exploited by remote attackers who craft malicious archive files, potentially resulting in application crashes or infinite loops. Moreover, there exists a risk of arbitrary code execution as a consequence of this flawed implementation, which is also linked to a regression from a previous vulnerability (CVE-2006-4334).

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.