CVE-2006-4337
EPSS 10.3%
Description
Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.
How to fix CVE-2006-4337
To remediate CVE-2006-4337, upgrade the affected package to a fixed version below.
- Debian/gzip—upgrade to 1.3.5-15 or later
Is CVE-2006-4337 being exploited?
Moderate — EPSS is 10.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.3.5-15