PT-2026-86403 · Ugrep · Ugrep
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ugrep versions prior to 7.6.0
Description
The LZW decompressor contains a heap buffer over-read when processing specially crafted .Z archive files. An attacker can provide malformed .Z files that cause the decompressor to read one byte beyond the allocated heap buffer, which may lead to a process crash. A heap buffer over-read occurs when a program reads more data from the heap than was originally allocated for that buffer.
Recommendations
Update to version 7.6.0 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ugrep