Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-4335

Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 83.1%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2006-4335
  • Gzip » Gzip » Version: 1.3.5
    cpe:2.3:a:gzip:gzip:1.3.5


Contact Us

Shodan ® - All rights reserved