CVE-2010-0001
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
- Gnu Gzip
- ≤ 1.3.13, 1.2.4, 1.2.4a, 1.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 4.8% (91th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2010-01-29
CVE-2010-0001 at NVD
1 known exploit for CVE-2010-0001
Proof-of-concept code and exploit modules indexed by Sploitus