ncompress: Buffer Underflow
Gentoo Linux Security Advisory
||GLSA 200610-03 / ncompress
||October 06, 2006
||October 06, 2006: 01
All supported architectures
A buffer underflow vulnerability has been reported in ncompress allowing
for the execution of arbitrary code.
ncompress is a suite of utilities to create and extract
Lempel-Ziff-Welch (LZW) compressed archives.
Tavis Ormandy of the Google Security Team discovered a static buffer
underflow in ncompress.
An attacker could create a specially crafted LZW archive, that when
decompressed by a user or automated system would result in the
execution of arbitrary code with the permissions of the user invoking
There is no known workaround at this time.
All ncompress users should upgrade to the latest version:
Code Listing 3.1: Resolution
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-arch/ncompress-220.127.116.11"