Lucene search

K
cveBc94ec7e-8909-4cbb-83df-d2fc9330fa88CVE-2006-1168
HistoryAug 14, 2006 - 8:04 p.m.

CVE-2006-1168

2006-08-1420:04:00
bc94ec7e-8909-4cbb-83df-d2fc9330fa88
web.nvd.nist.gov
43
cve-2006-1168
ncompress
liblzw
buffer underflow
denial of service
remote code execution
vulnerability.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

High

0.103 Low

EPSS

Percentile

95.0%

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

Affected configurations

NVD
Node
ncompressncompressMatch4.2.4
CPENameOperatorVersion
ncompress:ncompressncompresseq4.2.4

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

High

0.103 Low

EPSS

Percentile

95.0%