CVE-2009-2624

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive.  NOTE: this issue is caused by a CVE-2006-4334 regression.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
gnugzip
𝑥
≤ 1.3.12
gnugzip
1.2.4
gnugzip
1.2.4a:a
gnugzip
1.3
gnugzip
1.3.1
gnugzip
1.3.2
gnugzip
1.3.3
gnugzip
1.3.4
gnugzip
1.3.5
gnugzip
1.3.6
gnugzip
1.3.7
gnugzip
1.3.8
gnugzip
1.3.9
gnugzip
1.3.10
gnugzip
1.3.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gzip
bullseye (security)
1.10-4+deb11u1
fixed
bullseye
1.10-4+deb11u1
fixed
bookworm
1.12-1
fixed
sid
1.12-1.1
fixed
trixie
1.12-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gzip
karmic
not-affected
jaunty
Fixed 1.3.12-6ubuntu2.9.04.1
released
intrepid
Fixed 1.3.12-6ubuntu2.8.10.1
released
hardy
Fixed 1.3.12-3.2ubuntu0.1
released
dapper
Fixed 1.3.5-12ubuntu0.3
released