CVE-2010-0001
published 2010-01-29CVE-2010-0001: Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.77%
90.9th percentile
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | busybox | < gzip 1.3.12-9 (bookworm) | gzip 1.3.12-9 (bookworm) |
| debian | gzip | < gzip 1.3.12-9 (bookworm) | gzip 1.3.12-9 (bookworm) |
| debian | klibc | < gzip 1.3.12-9 (bookworm) | gzip 1.3.12-9 (bookworm) |
| debian | ncompress | < gzip 1.3.12-9 (bookworm) | gzip 1.3.12-9 (bookworm) |
| debian | pristine-tar | < gzip 1.3.12-9 (bookworm) | gzip 1.3.12-9 (bookworm) |
| gnu | gzip | <= 1.3.13 | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gnu | gzip | — | — |
| gzip | gzip | >= 0 < 1.3.12-9 | 1.3.12-9 |
| gzip | gzip | >= 0 < 1.3.12-9 | 1.3.12-9 |
| gzip | gzip | >= 0 < 1.3.12-9 | 1.3.12-9 |
| gzip | gzip | >= 0 < 1.3.12-9 | 1.3.12-9 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqhm-g528-h5pg: Integer underflow in the unlzw function in unlzw
ghsa_unreviewed·2022-05-02
CVE-2010-0001 [MEDIUM] GHSA-pqhm-g528-h5pg: Integer underflow in the unlzw function in unlzw
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
OSV
CVE-2010-0001: Integer underflow in the unlzw function in unlzw
osv·2010-01-29·CVSS 6.8
CVE-2010-0001 [MEDIUM] CVE-2010-0001: Integer underflow in the unlzw function in unlzw
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
Ubuntu
gzip vulnerabilities
vendor_ubuntu·2010-01-20·CVSS 6.8
CVE-2009-2624 [MEDIUM] gzip vulnerabilities
Title: gzip vulnerabilities
Summary: gzip vulnerabilities
It was discovered that gzip incorrectly handled certain malformed
compressed files. If a user or automated system were tricked into opening a
specially crafted gzip file, an attacker could cause gzip to crash or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-2624)
Aki Helin discovered that gzip incorrectly handled certain malformed
files compressed with the Lempel–Ziv–Welch (LZW) algorithm. If a user or
automated system were tricked into opening a specially crafted gzip file,
an attacker could cause gzip to crash or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0001)
Instructions: In general, a standard system upgrade is sufficient
Red Hat
gzip: (64 bit) Integer underflow by decompressing LZW format files
vendor_redhat·2010-01-20·CVSS 6.8
CVE-2010-0001 [MEDIUM] CWE-190 gzip: (64 bit) Integer underflow by decompressing LZW format files
gzip: (64 bit) Integer underflow by decompressing LZW format files
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
Debian
CVE-2010-0001: busybox - Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit ...
vendor_debian·2010·CVSS 6.8
CVE-2010-0001 [MEDIUM] CVE-2010-0001: busybox - Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit ...
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
Nuclei
ListSERV Maestro <= 9.0-8 RCE
nuclei·CVSS 5.0
CVE-2010-1870 [MEDIUM] ListSERV Maestro <= 9.0-8 RCE
ListSERV Maestro <= 9.0-8 RCE
A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.
Template:
id: CVE-2010-1870
info:
name: ListSERV Maestro <= 9.0-8 RCE
author: b0yd
severity: medium
description: A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Upgrade to a patched version of ListSERV Maestro that is not affected by this vulnerability.
reference:
- https://www.securifera.com/advisories/sec-2020-0001/
- https://packetstormsecurity.com/files/159643/listservmaestro-exec.txt
- https://www.exploit-db.com/exploits/1
arXiv
BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
arxiv_fulltext·2024-10-14
BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
BinSimDB: Benchmark Dataset Construction for Fine-Grained BCSA
Fei Zuo1( ) Cody Tompkins1
Qiang Zeng2 Lannan Luo2
Yung Ryn Choe3 Junghwan Rhee1
F. Zuo et al.
University of Central Oklahoma, Edmond, OK 73034, USA
\fzuo,ctompkins6,jrhee2\@uco.edu
George Mason University, Fairfax, VA 22030, USA
\zeng,lluo4\@gmu.edu
Sandia National Laboratories, Livermore, CA 94551, USA
[email protected]
## Abstract
Binary Code Similarity Analysis (BCSA) has a wide spectrum of applications, including plagiarism detection, vulnerability discovery, and malware analysis, thus drawing significant attention from the security community. However, conventional techniques often face challenges in balancing both accuracy
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-3170 [MEDIUM] CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Richard Moore and Simon Ward reported flaws in the way browsers such
as Firefox handled wildcard characters in the Common Name field of
a certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Firefox, the attacker could
use the certificate during the man-in-the-middle attack and potentially
confuse Firefox into accepting it by mistake. Different vulnerability than
CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335731
Discussion:
This will be fixed in NSS 3.12.8
---
Mozilla has assigned CVE-2010-3170 identifier to this issue.
Mozilla upstream bug:
[3]
Bugzilla
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-5076 [MEDIUM] CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
Richard Moore and Simon Ward reported flaw in the way Qt software toolkit
handled wildcard characters in the Common Name field of a x509v3 digital
certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Konqueror / Arora web browsers,
the attacker could use the certificate during the man-in-the-middle attack
and potentially confuse Konqueror / Arora into accepting it by mistake.
Different vulnerability than CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335730
Discussion:
Upstream commit addressing this issue:
http://qt.gitorious.org/qt/qt/commit/846f1b
Bugzilla
CVE-2010-0441 Asterisk: Remote DoS via specially-crafted FaxMaxDatagram SDP packets (AST-2010-001)
bugzilla·2010-02-03·CVSS 5.0
CVE-2010-0441 [MEDIUM] CVE-2010-0441 Asterisk: Remote DoS via specially-crafted FaxMaxDatagram SDP packets (AST-2010-001)
CVE-2010-0441 Asterisk: Remote DoS via specially-crafted FaxMaxDatagram SDP packets (AST-2010-001)
Remotely exploitable denial of service (crash) has been reported
and corrected in Asterisk. From the upstream advisory (AST-2010-0001):
"An attacker attempting to negotiate T.38 over SIP can remotely crash
Asterisk by modifying the FaxMaxDatagram field of the SDP to contain
either a negative or exceptionally large value. The same crash occurs
when the FaxMaxDatagram field is omitted from the SDP as well."
Upstream advisory:
http://downloads.asterisk.org/pub/security/AST-2010-001.pdf
Patches:
http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.0.diff (v1.6.0)
http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.1.diff (v1.6.1)
http://downloads.asterisk.org/pub/security/AST-2
Bugzilla
CVE-2010-0001 gzip: (64 bit) Integer underflow by decompressing LZW format files
bugzilla·2010-01-11·CVSS 6.8
CVE-2010-0001 [MEDIUM] CVE-2010-0001 gzip: (64 bit) Integer underflow by decompressing LZW format files
CVE-2010-0001 gzip: (64 bit) Integer underflow by decompressing LZW format files
An integer underflow leading to array index error was found in the way
gzip used to decompress files / archives, compressed with the Lempel–Ziv–Welch
(LZW) compression algorithm. A remote attacker could provide a
specially-crafted LZW compressed gzip archive, which once decompressed
by a local, unsuspecting user would lead to gzip crash, or, potentially to arbitrary code execution with the privileges of the user running gzip.
Upstream patch:
http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468f
Acknowledgements:
Red Hat would like to thank Aki Helin of the Oulu University Secure
Programming Group for responsibly reporting this flaw.
Discussion:
This issue affects t
http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468fhttp://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlhttp://ncompress.sourceforge.net/#statushttp://savannah.gnu.org/forum/forum.php?forum_id=6153http://secunia.com/advisories/38220http://secunia.com/advisories/38223http://secunia.com/advisories/38225http://secunia.com/advisories/38232http://secunia.com/advisories/40551http://secunia.com/advisories/40655http://secunia.com/advisories/40689http://securitytracker.com/id?1023490http://support.apple.com/kb/HT4435http://www.debian.org/security/2010/dsa-1974http://www.debian.org/security/2010/dsa-2074http://www.mandriva.com/security/advisories?name=MDVSA-2010:019http://www.mandriva.com/security/advisories?name=MDVSA-2010:020http://www.mandriva.com/security/advisories?name=MDVSA-2011:152http://www.osvdb.org/61869http://www.redhat.com/support/errata/RHSA-2010-0061.htmlhttp://www.ubuntu.com/usn/USN-889-1http://www.vupen.com/english/advisories/2010/0185http://www.vupen.com/english/advisories/2010/1796http://www.vupen.com/english/advisories/2010/1872https://bugzilla.redhat.com/show_bug.cgi?id=554418https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10546https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7511https://rhn.redhat.com/errata/RHSA-2010-0095.htmlhttp://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468fhttp://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlhttp://ncompress.sourceforge.net/#statushttp://savannah.gnu.org/forum/forum.php?forum_id=6153http://secunia.com/advisories/38220http://secunia.com/advisories/38223http://secunia.com/advisories/38225http://secunia.com/advisories/38232http://secunia.com/advisories/40551http://secunia.com/advisories/40655http://secunia.com/advisories/40689http://securitytracker.com/id?1023490http://support.apple.com/kb/HT4435http://www.debian.org/security/2010/dsa-1974http://www.debian.org/security/2010/dsa-2074http://www.mandriva.com/security/advisories?name=MDVSA-2010:019http://www.mandriva.com/security/advisories?name=MDVSA-2010:020http://www.mandriva.com/security/advisories?name=MDVSA-2011:152http://www.osvdb.org/61869http://www.redhat.com/support/errata/RHSA-2010-0061.htmlhttp://www.ubuntu.com/usn/USN-889-1http://www.vupen.com/english/advisories/2010/0185http://www.vupen.com/english/advisories/2010/1796http://www.vupen.com/english/advisories/2010/1872https://bugzilla.redhat.com/show_bug.cgi?id=554418https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10546https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7511https://rhn.redhat.com/errata/RHSA-2010-0095.html
2010-01-29
Published