PublicDate: 2006-08-14 20:04:00 UTC Candidate: CVE-2006-1168 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1168 Description: The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_ncompress: released (4.2.4-15sarge2build0.6.06.1) edgy_ncompress: released (4.2.4-15sarge2) feisty_ncompress: released (4.2.4-15sarge2) gutsy_ncompress: released (4.2.4-15sarge2) hardy_ncompress: released (4.2.4-15sarge2) intrepid_ncompress: released (4.2.4-15sarge2) jaunty_ncompress: released (4.2.4-15sarge2) devel_ncompress: released (4.2.4-15sarge2) upstream_ncompress: needs-triage