CVE-2006-1168

Publication date 14 August 2006

Last updated 24 July 2024


Ubuntu priority

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
ncompress 9.04 jaunty
Fixed 4.2.4-15sarge2
8.10 intrepid
Fixed 4.2.4-15sarge2
8.04 LTS hardy
Fixed 4.2.4-15sarge2
7.10 gutsy
Fixed 4.2.4-15sarge2
7.04 feisty
Fixed 4.2.4-15sarge2
6.10 edgy
Fixed 4.2.4-15sarge2
6.06 LTS dapper
Fixed 4.2.4-15sarge2build0.6.06.1