← Vulnerability feed

Vulnerability record · CVE-2006-4334 · published 19 September 2006

CVE-2006-4334: Gzip vulnerability

Gzip · Gzip

Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.

5.0 CVSS 2.0 Medium EPSS 4.1% · top 9.5%
5.0CVSS 2.0 base score
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
104References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=204676
http://docs.info.apple.com/article.html?artnum=304829
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
http://secunia.com/advisories/21996
http://secunia.com/advisories/22002
http://secunia.com/advisories/22009
http://secunia.com/advisories/22012
http://secunia.com/advisories/22017
http://secunia.com/advisories/22027
http://secunia.com/advisories/22033
http://secunia.com/advisories/22034
http://secunia.com/advisories/22043
http://secunia.com/advisories/22085
http://secunia.com/advisories/22101
http://secunia.com/advisories/22435
http://secunia.com/advisories/22487
http://secunia.com/advisories/22661
http://secunia.com/advisories/23155
http://secunia.com/advisories/23679
http://secunia.com/advisories/24435
http://secunia.com/advisories/24636
http://security.freebsd.org/advisories/FreeBSD-SA-06:21.gzip.asc
http://security.gentoo.org/glsa/glsa-200609-13.xml
http://securitytracker.com/id?1016883
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102766-1
http://support.avaya.com/elmodocs2/security/ASA-2006-218.htm
http://www.kb.cert.org/vuls/id/933712 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2006:167
http://www.novell.com/linux/security/advisories/2006_56_gzip.html
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.020-gzip.html
http://www.redhat.com/support/errata/RHSA-2006-0667.html
http://www.securityfocus.com/archive/1/446426/100/0/threaded
http://www.securityfocus.com/archive/1/450078/100/0/threaded
http://www.securityfocus.com/archive/1/451324/100/0/threaded
http://www.securityfocus.com/archive/1/462007/100/0/threaded
http://www.securityfocus.com/archive/1/464268/100/0/threaded
http://www.securityfocus.com/bid/20101
http://www.trustix.org/errata/2006/0052/

Track CVE-2006-4334 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-4334), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.