CVE-2010-0001

Severity
6.8MEDIUM
EPSS
22.6%
top 4.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateMay 2

Description

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Debiangzip< 1.3.12-9+3
Debianncompress< 4.2.4.3-1+3
NVDgnu/gzip1.3.13+15

🔴Vulnerability Details

3
GHSA
GHSA-pqhm-g528-h5pg: Integer underflow in the unlzw function in unlzw2022-05-02
OSV
CVE-2010-0001: Integer underflow in the unlzw function in unlzw2010-01-29
CVEList
CVE-2010-0001: Integer underflow in the unlzw function in unlzw2010-01-29

💥Exploits & PoCs

1
Nuclei
ListSERV Maestro <= 9.0-8 RCE

📋Vendor Advisories

3
Ubuntu
gzip vulnerabilities2010-01-20
Red Hat
gzip: (64 bit) Integer underflow by decompressing LZW format files2010-01-20
Debian
CVE-2010-0001: busybox - Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit ...2010

💬Community

4
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely2010-09-03
Bugzilla
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name2010-09-03
Bugzilla
CVE-2010-0441 Asterisk: Remote DoS via specially-crafted FaxMaxDatagram SDP packets (AST-2010-001)2010-02-03
Bugzilla
CVE-2010-0001 gzip: (64 bit) Integer underflow by decompressing LZW format files2010-01-11