Vulnerabilities
Vulnerable Software
Ncompress:  Security Vulnerabilities
The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.
CVSS Score
7.5
EPSS Score
0.098
Published
2006-08-14
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-09-20
Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.
CVSS Score
7.5
EPSS Score
0.129
Published
2004-12-23


Contact Us

Shodan ® - All rights reserved