Unrated severityNVD Advisory· Published Jan 29, 2010· Updated Apr 29, 2026
CVE-2010-0001
CVE-2010-0001
Description
Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.
Affected products
16cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*range: <=1.3.13
- cpe:2.3:a:gnu:gzip:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.2.4a:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gzip:1.3.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- secunia.com/advisories/38220nvdVendor Advisory
- secunia.com/advisories/38223nvdVendor Advisory
- secunia.com/advisories/38225nvdVendor Advisory
- secunia.com/advisories/38232nvdVendor Advisory
- www.vupen.com/english/advisories/2010/0185nvdVendor Advisory
- git.savannah.gnu.org/cgit/gzip.git/commit/nvd
- itrc.hp.com/service/cki/docDisplay.donvd
- kb.juniper.net/InfoCenter/indexnvd
- lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.htmlnvd
- ncompress.sourceforge.netnvd
- secunia.com/advisories/40551nvd
- secunia.com/advisories/40655nvd
- secunia.com/advisories/40689nvd
- securitytracker.com/idnvd
- support.apple.com/kb/HT4435nvd
- www.debian.org/security/2010/dsa-1974nvd
- www.debian.org/security/2010/dsa-2074nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.osvdb.org/61869nvd
- www.redhat.com/support/errata/RHSA-2010-0061.htmlnvd
- www.ubuntu.com/usn/USN-889-1nvd
- www.vupen.com/english/advisories/2010/1796nvd
- www.vupen.com/english/advisories/2010/1872nvd
- bugzilla.redhat.com/show_bug.cginvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10546nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7511nvd
- rhn.redhat.com/errata/RHSA-2010-0095.htmlnvd
News mentions
0No linked articles in our index yet.