Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Gnuzip | — | Apply OS X security update 2006-007 | Dec 16, 2011 | Sep 19, 2006 |
| Debian | — | Upgrade gzip | Jul 30, 2024 | Sep 19, 2006 |
| Freebsd | — | Upgrade gzipUpgrade FreeBSD | Dec 10, 2025 | Dec 19, 2006 |
| Gentoo Linux | — | Upgrade app-arch/lha.Upgrade app-arch/gzip. | Oct 30, 2017 | Sep 19, 2006 |
| Hpux | — | Update SW-DIST.SD-CMDS to the latest versionUpdate SW-DIST.GZIP to the latest versionUpdate SW-DIST.SD-AGENT to the latest versionApply patch PHCO_35587 from HP | Aug 11, 2017 | Sep 19, 2006 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 2, 2006 |
| Suse | — | Upgrade gzip | Feb 17, 2015 | Sep 19, 2006 |
| Ubuntu | — | Upgrade gzip | Nov 8, 2024 | Sep 19, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub