Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

GZip Long File Name Buffer Overflow Vulnerability

gzip is a freely available, open source file compression utility. It is maintained and distributed by GNU.

gzip does not properly handle long file names. Upon execution of the program with a file name of 1028 bytes or greater, a buffer overflow occurs. This overflow could overwrite stack variables, including the return address, and be used to execute arbitrary code.







 

Privacy Statement
Copyright 2007, SecurityFocus