- What: Multiple vulnerabilities in gzip allow a local attacker to manipulate files and disclose sensitive information
- Impact: Affected systems include UNIX and Windows environments using the gzip utility
[WID-SEC-2026-2126] gzip: Mehrere Schwachstellen CVSS Base Score 6.2 (mittel) CVSS Temporal Score 5.4 (mittel) Remoteangriff nein Datum 29.06.2026 Stand 30.06.2026 Mitigation ja Betroffene Systeme Betriebssystem UNIX Windows Produktbeschreibung Das gzip-Paket ist ein GNU Kompressionsprogramm. Produkte 29.06.2026 Open Source gzip commit <63dbf6b3b9e6e781df1a6a64e609b10e23969681 Open Source gzip commit <4e6f8b24ab823146ab8776f0b7fe486ab34d4269 Angriff Angriff Ein lokaler Angreifer kann mehrere Schwachstellen in gzip ausnutzen, um Dateien zu manipulieren und um vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben