GNU gzip LZW Compression Remote Integer Overflow Vulnerability
BID:37886
Info
GNU gzip LZW Compression Remote Integer Overflow Vulnerability
| Bugtraq ID: | 37886 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0001 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2010 12:00AM |
| Updated: | Apr 16 2015 06:13PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
VMWare vMA 4.0 RHEL5 VMWare vMA 4.0 VMWare ESX Server 4.0 Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Client 2008 Turbolinux Appliance Server 3.0 x64 Turbolinux Appliance Server 3.0 Slackware Linux x86_64 -current Slackware Linux 13.0 x86_64 Slackware Linux 13.0 rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 2 rPath Appliance Platform Linux Service 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop version 4 RedHat Desktop 3.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server Pardus Linux 2009 0 ncompress ncompress 4.2.4 2 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 HP Insight Control 6.0 HP Insight Control 0 GNU gzip 1.3.12 GNU gzip 1.3.5 GNU gzip 1.3.4 GNU gzip 1.3.3 t GNU gzip 1.3.3 GNU gzip 1.3.2 GNU gzip 1.3 GNU gzip 1.2.4 a GNU gzip 1.2.4 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Aura System Platform SP1.1 Avaya Aura System Platform 6.0 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.6 |
| Not Vulnerable: |
VMWare ESX Server 4.0 ESX400-201005405 ncompress ncompress 4.2.4 3 HP Insight Control 6.1 Apple Mac OS X Server 10.6.5 |
Discussion
GNU gzip LZW Compression Remote Integer Overflow Vulnerability
GNU gzip is prone to a remote integer-underflow vulnerability because it fails to sufficiently validate an integer value before using it to index an array.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
GNU gzip is prone to a remote integer-underflow vulnerability because it fails to sufficiently validate an integer value before using it to index an array.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
GNU gzip LZW Compression Remote Integer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GNU gzip LZW Compression Remote Integer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
Debian Linux 5.0 ia-64
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Apple Mac OS X Server 10.6
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 6.06 LTS sparc
Debian Linux 5.0 alpha
Mandriva Linux Mandrake 2008.0 x86_64
Ubuntu Ubuntu Linux 8.04 LTS amd64
Mandriva Linux Mandrake 2008.0
Ubuntu Ubuntu Linux 9.10 lpia
Mandriva Linux Mandrake 2010.1 x86_64
Debian Linux 5.0 mipsel
Ubuntu Ubuntu Linux 9.04 sparc
Mandriva Linux Mandrake 2010.0
Ubuntu Ubuntu Linux 9.04 powerpc
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 hppa
Ubuntu Ubuntu Linux 9.04 i386
Ubuntu Ubuntu Linux 9.04 lpia
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 9.10 i386
Turbolinux Turbolinux Server 10.0.0 x64
Debian Linux 5.0 armel
Debian Linux 5.0
Ubuntu Ubuntu Linux 9.10 amd64
Apple Mac OS X 10.6
Debian Linux 4.0 mipsel
Mandriva Linux Mandrake 2009.0 x86_64
Debian Linux 5.0 mips
Ubuntu Ubuntu Linux 9.04 amd64
Mandriva Linux Mandrake 2009.1
Ubuntu Ubuntu Linux 8.10 amd64
Debian Linux 4.0 ia-64
Debian Linux 5.0 sparc
Debian Linux 4.0 arm
Mandriva Linux Mandrake 2009.1 x86_64
Debian Linux 4.0 powerpc
Ubuntu Ubuntu Linux 8.10 i386
MandrakeSoft Enterprise Server 5 x86_64
Apple Mac OS X Server 10.6.1
Apple Mac OS X 10.6.1
Apple Mac OS X Server 10.6.2
Apple Mac OS X 10.6.3
Apple Mac OS X 10.6.4
Apple Mac OS X Server 10.6.4
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu gzip_1.3.12-8ubuntu1.1_sparc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-8ubuntu1.1_sparc. deb
Debian Linux 5.0 ia-64
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb -
Debian gzip_1.3.12-6+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.12-6+lenn y1_ia64.deb -
Debian ncompress_4.2.4.2-1+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/n/ncompress/ncompress_4.2 .4.2-1+lenny1_ia64.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu gzip_1.3.12-3.2ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-3.2ubuntu0.1_powe rpc.deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu gzip_1.3.12-6ubuntu2.8.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-6ubuntu2.8.10.1_p owerpc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu gzip_1.3.12-3.2ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-3.2ubuntu0.1_spar c.deb
Apple Mac OS X Server 10.6
-
Apple MacOSXServUpdCombo10.6.5.dmg
For Mac OS X Server v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu gzip_1.3.12-8ubuntu1.1_powerpc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-8ubuntu1.1_powerp c.deb
Ubuntu Ubuntu Linux 6.06 LTS sparc
-
Ubuntu gzip_1.3.5-12ubuntu0.3_sparc.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.5-12ubuntu 0.3_sparc.deb
Debian Linux 5.0 alpha
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb -
Debian gzip_1.3.12-6+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.12-6+lenn y1_alpha.deb -
Debian ncompress_4.2.4.2-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/n/ncompress/ncompress_4.2 .4.2-1+lenny1_alpha.deb
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva gzip-1.3.12-1.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu gzip_1.3.12-3.2ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-3.2ubun tu0.1_amd64.deb
Mandriva Linux Mandrake 2008.0
-
Mandriva gzip-1.3.12-1.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu gzip_1.3.12-8ubuntu1.1_lpia.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-8ubuntu1.1_lpia.d eb
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva ncompress-4.2.4.4-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Debian Linux 5.0 mipsel
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb -
Debian gzip_1.3.12-6+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.12-6+lenn y1_mipsel.deb -
Debian ncompress_4.2.4.2-1+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/n/ncompress/ncompress_4.2 .4.2-1+lenny1_mipsel.deb
Ubuntu Ubuntu Linux 9.04 sparc
-
Ubuntu gzip_1.3.12-6ubuntu2.9.04.1_sparc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-6ubuntu2.9.04.1_s parc.deb
Mandriva Linux Mandrake 2010.0
-
Mandriva gzip-1.3.12-5.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.04 powerpc
-
Ubuntu gzip_1.3.12-6ubuntu2.9.04.1_powerpc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-6ubuntu2.9.04.1_p owerpc.deb
Debian Linux 4.0 amd64
-
Debian gzip_1.3.5-15+etch1_amd64.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_amd64.deb
Debian Linux 4.0 ia-32
-
Debian gzip_1.3.5-15+etch1_i386.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_i386.deb
Debian Linux 4.0 hppa
-
Debian gzip_1.3.5-15+etch1_hppa.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_hppa.deb
Ubuntu Ubuntu Linux 9.04 i386
-
Ubuntu gzip_1.3.12-6ubuntu2.9.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-6ubuntu 2.9.04.1_i386.deb
Ubuntu Ubuntu Linux 9.04 lpia
-
Ubuntu gzip_1.3.12-6ubuntu2.9.04.1_lpia.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-6ubuntu2.9.04.1_l pia.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu gzip_1.3.12-6ubuntu2.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/g/gzip/gzip_1.3.12-6ubuntu2.8.10.1_s parc.deb
Ubuntu Ubuntu Linux 9.10 i386
-
Ubuntu gzip_1.3.12-8ubuntu1.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-8ubuntu 1.1_i386.deb
Turbolinux Turbolinux Server 10.0.0 x64
-
Turbolinux gzip-1.3.3-10.x86_64.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/x64/Server/10/upd ates/RPMS/gzip-1.3.3-10.x86_64.rpm
Debian Linux 5.0 armel
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb -
Debian gzip_1.3.12-6+lenny1_armel.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.12-6+lenn y1_armel.deb -
Debian ncompress_4.2.4.2-1+lenny1_armel.deb
http://security.debian.org/pool/updates/main/n/ncompress/ncompress_4.2 .4.2-1+lenny1_armel.deb
Debian Linux 5.0
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu gzip_1.3.12-8ubuntu1.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-8ubuntu 1.1_amd64.deb
Apple Mac OS X 10.6
-
Apple MacOSXUpdCombo10.6.5.dmg
For Mac OS X v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Debian Linux 4.0 mipsel
-
Debian gzip_1.3.5-15+etch1_mipsel.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_mipsel.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva gzip-1.3.12-3.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 5.0 mips
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb -
Debian ncompress_4.2.4.2-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/n/ncompress/ncompress_4.2 .4.2-1+lenny1_mips.deb
Ubuntu Ubuntu Linux 9.04 amd64
-
Ubuntu gzip_1.3.12-6ubuntu2.9.04.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-6ubuntu 2.9.04.1_amd64.deb
Mandriva Linux Mandrake 2009.1
-
Mandriva gzip-1.3.12-4.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu gzip_1.3.12-6ubuntu2.8.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-6ubuntu 2.8.10.1_amd64.deb
Debian Linux 4.0 ia-64
-
Debian gzip_1.3.5-15+etch1_ia64.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_ia64.deb
Debian Linux 5.0 sparc
-
Debian gzip-win32_1.3.12-6+lenny1_all.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip-win32_1.3.12- 6+lenny1_all.deb -
Debian gzip_1.3.12-6+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.12-6+lenn y1_sparc.deb -
Debian ncompress_4.2.4.2-1+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/n/ncompress/ncompress_4.2 .4.2-1+lenny1_sparc.deb
Debian Linux 4.0 arm
-
Debian gzip_1.3.5-15+etch1_arm.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_arm.deb
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva gzip-1.3.12-4.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 powerpc
-
Debian gzip_1.3.5-15+etch1_powerpc.deb
http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.5-15+etch 1_powerpc.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu gzip_1.3.12-6ubuntu2.8.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/g/gzip/gzip_1.3.12-6ubuntu 2.8.10.1_i386.deb
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva gzip-1.3.12-3.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva ncompress-4.2.4.4-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Apple Mac OS X Server 10.6.1
-
Apple MacOSXServUpdCombo10.6.5.dmg
For Mac OS X Server v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.1
-
Apple MacOSXUpdCombo10.6.5.dmg
For Mac OS X v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.2
-
Apple MacOSXServUpdCombo10.6.5.dmg
For Mac OS X Server v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.3
-
Apple MacOSXUpdCombo10.6.5.dmg
For Mac OS X v10.6 - v10.6.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.4
-
Apple MacOSXUpd10.6.5.dmg
For Mac OS X v10.6.4
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.4
-
Apple MacOSXServerUpd10.6.5.dmg
For Mac OS X Server v10.6.4
http://www.apple.com/support/downloads/
References
GNU gzip LZW Compression Remote Integer Overflow Vulnerability
References:
References:
- gzip Homepage (GNU)
- ncompress (ncompress)
- ASA-2010-049 gzip security update (RHSA-2010-0061) (Avaya)