Unrated severityNVD Advisory· Published Jan 29, 2010· Updated Apr 29, 2026
CVE-2009-2624
CVE-2009-2624
Description
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
Affected products
15cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*range: <=1.3.12
- cpe:2.3:a:gnu:gzip:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.2.4a:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- secunia.com/advisories/38132nvdVendor Advisory
- secunia.com/advisories/38223nvdVendor Advisory
- secunia.com/advisories/38232nvdVendor Advisory
- article.gmane.org/gmane.comp.gnu.gzip.bugs/258nvd
- bugs.debian.org/cgi-bin/bugreport.cginvd
- git.savannah.gnu.org/cgit/gzip.git/commit/nvd
- lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlnvd
- support.apple.com/kb/HT4435nvd
- www.debian.org/security/2010/dsa-1974nvd
- www.mandriva.com/security/advisoriesnvd
- www.ubuntu.com/usn/USN-889-1nvd
- www.vupen.com/english/advisories/2010/0185nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.