cbcvebase.
CVE-2010-0001
published 2010-01-29

CVE-2010-0001: Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to…

PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.77%
90.9th percentile
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianbusybox< gzip 1.3.12-9 (bookworm)gzip 1.3.12-9 (bookworm)
debiangzip< gzip 1.3.12-9 (bookworm)gzip 1.3.12-9 (bookworm)
debianklibc< gzip 1.3.12-9 (bookworm)gzip 1.3.12-9 (bookworm)
debianncompress< gzip 1.3.12-9 (bookworm)gzip 1.3.12-9 (bookworm)
debianpristine-tar< gzip 1.3.12-9 (bookworm)gzip 1.3.12-9 (bookworm)
gnugzip<= 1.3.13
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gnugzip
gzipgzip>= 0 < 1.3.12-91.3.12-9
gzipgzip>= 0 < 1.3.12-91.3.12-9
gzipgzip>= 0 < 1.3.12-91.3.12-9
gzipgzip>= 0 < 1.3.12-91.3.12-9

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.