VYPR

Ncompress

by Ncompress

CVEs (3)

  • CVE-2006-1168Aug 14, 2006
    risk 0.01cvss epss 0.10

    The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

  • CVE-2001-1413Dec 23, 2004
    risk 0.01cvss epss 0.09

    Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.

  • CVE-2005-2991Sep 20, 2005
    risk 0.00cvss epss 0.00

    ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.