GNU
GNU Gzip: vulnerabilidades y CVE
GNU Gzip tiene 13 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41992 | Media (6.9) | 0.56% | — | 29 jun 2026 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip… |
| CVE-2026-41991 | Baja (2) | 0.14% | — | 29 jun 2026 | GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path… |
| CVE-2022-1271 | Alta (8.8) | 5.1% | — | 31 ago 2022 | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an… |
| CVE-2010-0001 | Media (6.8) | 4.8% | — | 29 ene 2010 | Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly… |
| CVE-2009-2624 | Media (6.8) | 4.2% | — | 29 ene 2010 | The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or… |
| CVE-2005-0758 | Media (4.6) | 0.53% | — | 13 may 2005 | zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script. |
| CVE-2005-0988 | Baja (3.7) | 0.66% | — | 2 may 2005 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose… |
| CVE-2005-1228 | Media (5) | 3.6% | — | 2 may 2005 | Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file. |
| CVE-2004-0970 | Baja (2.1) | 0.36% | — | 9 feb 2005 | The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew… |
| CVE-2004-0603 | Alta (10) | 3.1% | — | 6 dic 2004 | gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a… |
| CVE-2004-1349 | Baja (2.1) | 0.59% | — | 4 oct 2004 | gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files. |
| CVE-2003-0367 | Baja (2.1) | 0.44% | — | 2 jul 2003 | znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
| CVE-2001-1228 | Alta (7.5) | 3.1% | — | 18 nov 2001 | Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server. |