unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Gnuzip | — | Apply OS X security update 2006-007 | Dec 16, 2011 | Sep 19, 2006 |
| Debian | — | Upgrade gzip | Jul 30, 2024 | Sep 19, 2006 |
| Freebsd | — | Upgrade FreeBSDUpgrade gzip | Dec 10, 2025 | Dec 19, 2006 |
| Gentoo Linux | — | Upgrade app-arch/gzip.Upgrade app-arch/lha. | Oct 30, 2017 | Sep 19, 2006 |
| Hpux | — | Update SW-DIST.SD-AGENT to the latest versionApply patch PHCO_35587 from HPUpdate SW-DIST.SD-CMDS to the latest versionUpdate SW-DIST.GZIP to the latest version | Aug 11, 2017 | Sep 19, 2006 |
| Suse | — | Upgrade gzip | Feb 17, 2015 | Sep 19, 2006 |
| Ubuntu | — | Upgrade gzip | Nov 8, 2024 | Sep 19, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub