cbcvebase.
CVE-2009-2624
published 2010-01-29

CVE-2009-2624: The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a…

PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.18%
89.8th percentile
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiangzip< gzip 1.3.12-8 (bookworm)gzip 1.3.12-8 (bookworm)
gnugzip<= 1.3.12
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gzipgzip>= 0 < 1.3.12-81.3.12-8
gzipgzip>= 0 < 1.3.12-81.3.12-8
gzipgzip>= 0 < 1.3.12-81.3.12-8
gzipgzip>= 0 < 1.3.12-81.3.12-8

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.0MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.