SAP LZC/LZH Compression Denial Of Service

Discussion in 'News Aggregator' started by Packet Storm, 14 May 2015.

  1. Packet Storm

    Packet Storm Guest

    Core Security Technologies Advisory - SAP products make use of a proprietary implementation of the Lempel-Ziv-Thomas (LZC) adaptive dictionary compression algorithm and the Lempel-Ziv-Huffman (LZH) compression algorithm. These compression algorithms are used across several SAP products and programs. Vulnerabilities were found in the decompression routines that could be triggered in different scenarios, and could lead to execution of arbitrary code and denial of service conditions.

    Continue reading...
     

Share This Page

Loading...