| CVE-2010-0001 |
| 기본정보 |
- 공개일 : 2010-01-30
- 변경일 : 2011-10-26
|
| CVSS 평가 |
- 위험도: 6.8
-
액세스 벡터
:
NETWORK
-
액세스 복잡성
:
보통
-
인증
:
없음
-
기밀성 영향
:
부분
-
무결성 영향
:
부분
-
가용성 영향
:
부분
-
출처
:
http://nvd.nist.gov
-
공개일
:
2010-02-01
|
| 설명 |
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
|
| 참조 |
- REDHAT, RHSA-2010:0095
- CONFIRM, https://bugzilla.redhat.com/show_bug.cgi?id=554418
- VUPEN, ADV-2010-1872
- VUPEN, ADV-2010-1796
- VUPEN, ADV-2010-0185
- UBUNTU, USN-889-1
- REDHAT, RHSA-2010:0061
- OSVDB, 61869
- MANDRIVA, MDVSA-2011:152
- MANDRIVA, MDVSA-2010:020
- MANDRIVA, MDVSA-2010:019
- DEBIAN, DSA-2074
- DEBIAN, DSA-1974
- CONFIRM, http://support.apple.com/kb/HT4435
- SECTRACK, 1023490
- SECUNIA, 40689
- SECUNIA, 40655
- SECUNIA, 40551
- SECUNIA, 38232
- SECUNIA, 38225
- SECUNIA, 38223
- SECUNIA, 38220
- CONFIRM, http://savannah.gnu.org/forum/forum.php?forum_id=6153
- CONFIRM, http://ncompress.sourceforge.net/#status
- SUSE, SUSE-SA:2010:008
- APPLE, APPLE-SA-2010-11-10-1
- HP, HPSBMA02554
- HP, HPSBMA02554
- CONFIRM, http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b..
|
| 취약 소프트웨어 |
-
gnu
gzip
1.3.13
-
gnu
gzip
1.3.1
-
gnu
gzip
1.3.12
-
gnu
gzip
1.3.8
-
gnu
gzip
1.3.4
-
gnu
gzip
1.3.3
-
gnu
gzip
1.3.7
-
gnu
gzip
1.3.5
-
gnu
gzip
1.3.9
-
gnu
gzip
1.2.4
-
gnu
gzip
1.3
-
gnu
gzip
1.3.2
-
gnu
gzip
1.2.4a
-
gnu
gzip
1.3.11
-
gnu
gzip
1.3.6
-
gnu
gzip
1.3.10
|