Thiemo Nagel reported (to the Debian project) that a specially-crafted file could cause gzip to segfault or hang. The file is attached below.
Also attached is a patch that addresses the problem. With this patch attached, gzip will simply report a malformed input file and exit as desired. -Carl
segv.gz
Description: GNU Zip compressed data
0001-Avoid-creating-an-undersized-buffer-for-the-hufts-ta.patch
Description: application/mbox
signature.asc
Description: This is a digitally signed message part