CVE-2009-2624

Priority
Medium
Description
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts
(aka huffman) table that is too small, which allows remote attackers to
cause a denial of service (application crash or infinite loop) or possibly
execute arbitrary code via a crafted archive. NOTE: this issue is caused
by a CVE-2006-4334 regression.
References
Assigned-to
mdeslaur
Package
Source: gzip (LP Ubuntu Debian)
Upstream:released (1.3.12-8)
Ubuntu 8.04 LTS (Hardy Heron):released (1.3.12-3.2ubuntu0.1)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected (1.3.12-9ubuntu1)
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:20:00 UTC (commit 5347)