Lucene search

K
cve[email protected]CVE-2009-1216
HistoryApr 01, 2009 - 6:00 p.m.

CVE-2009-1216

2009-04-0118:00:00
web.nvd.nist.gov
24
cve-2009-1216
gzip libraries
microsoft windows server
remote code execution
nvd
vulnerability
security
exploit

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.2 Low

EPSS

Percentile

96.4%

Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA); as used in gunzip, gzip, pack, pcat, and unpack 7.x before 7.0.1701.48, 8.x before 8.0.1969.62, and 9.x before 9.0.3790.2076; allow remote attackers to execute arbitrary code via unknown vectors.

Affected configurations

NVD
Node
microsoftsubsystem_for_unix-based_applications
OR
microsoftwindows_services_for_unixMatch3.0-std
OR
microsoftwindows_services_for_unixMatch3.5
OR
microsoftwindows_server_2008
OR
microsoftwindows_vista
OR
microsoftwindows_vistaenterprise
OR
microsoftwindows_vistaultimate

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.2 Low

EPSS

Percentile

96.4%

Related for CVE-2009-1216