Zlib Compression Library Denial Of Service Vulnerability

BID:11051

Info

Zlib Compression Library Denial Of Service Vulnerability

Bugtraq ID: 11051
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: Yes
Published: Aug 25 2004 12:00AM
Updated: Jan 10 2006 11:33PM
Credit: Johan Thelmen <[email protected]> reported this vulnerability to Debian GNU/Linux.
Vulnerable: zlib zlib 1.2.1
+ Redhat Fedora Core2
+ Turbolinux Turbolinux Server 10.0
zlib zlib 1.2 .0.7
+ Redhat Fedora Core1
Trustix Secure Linux 3.0
Trustix Secure Linux 2.2
Trustix Secure Enterprise Linux 2.0
SuSE Linux Enterprise Server 9
SCO Unixware 7.1.4
SCO Unixware 7.1.3 up
SCO Unixware 7.1.3
SCO Unixware 7.1.2
SCO Unixware 7.1.1
SCO Unixware 7.1
SCO Unixware 7.0.1
SCO Unixware 7.0
SCO Open Server 6.0
SCO Open Server 5.0.7
SCO Open Server 5.0.6 a
SCO Open Server 5.0.6
S.u.S.E. Linux Personal 9.1
Redhat Fedora Core2
OpenPKG OpenPKG 2.3
OpenPKG OpenPKG 2.2
OpenPKG OpenPKG 2.1
OpenPKG OpenPKG 2.0
OpenPKG OpenPKG Current
OpenBSD OpenBSD 3.5
OpenBSD OpenBSD -current
Mandriva Linux Mandrake 10.0 AMD64
Mandriva Linux Mandrake 10.0
MacSSH MacSSH 2.1 fc3
MacSFTP MacSFTP 1.0.6
libpng libpng3 1.2.6
libpng libpng 1.0.16
FileZilla FileZilla Server 0.7.1
FileZilla FileZilla Server 0.7
CVS CVS 1.12.12
Avaya Intuity R5 R5.1.46
Not Vulnerable: zlib zlib 1.2.2
+ zsync zsync 0.4
+ zsync zsync 0.3.3
+ zsync zsync 0.3.2
+ zsync zsync 0.3.1
+ zsync zsync 0.3
+ zsync zsync 0.2.3
+ zsync zsync 0.2.2
+ zsync zsync 0.2.1
+ zsync zsync 0.2
+ zsync zsync 0.1.6
+ zsync zsync 0.1.5
+ zsync zsync 0.1.4
+ zsync zsync 0.1.3
+ zsync zsync 0.1.2
+ zsync zsync 0.1.1
+ zsync zsync 0.1
+ zsync zsync 0.0.6
+ zsync zsync 0.0.5
+ zsync zsync 0.0.4
+ zsync zsync 0.0.3
+ zsync zsync 0.0.2
+ zsync zsync 0.0.1
libpng libpng3 1.2.7
+ Trustix Secure Enterprise Linux 2.0
libpng libpng 1.0.17
CVS CVS 1.12.13

Discussion

Zlib Compression Library Denial Of Service Vulnerability

The Zlib compression library is reportedly susceptible to a denial of service vulnerability. This vulnerability is caused by a failure of the application to properly handle malformed input during the decompression process.

This vulnerability is reported to exist in version 1.2.1 of the library. Other versions are also likely affected.

Exploit / POC

Zlib Compression Library Denial Of Service Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Zlib Compression Library Denial Of Service Vulnerability

Solution:
SuSE Linux has released advisory SUSE-SA:2004:029 along with fixes dealing with this issue. Please see the referenced advisory for more information.

OpenPKG has released an advisory (OpenPKG-SA-2004.038) along with fixes to address this issue. Please see the referenced advisory for further information.

Trustix Linux has released advisory TSL-2004-0043 dealing with this and other issues. Please see the referenced advisory for more information.

Gentoo has released an advisory (GLSA 200408-26) to address this issue. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to update their computers:

emerge sync
emerge -pv ">=net-im/gaim-0.81-r5"
emerge ">=net-im/gaim-0.81-r5"

OpenBSD has released a patch dealing with this issue. Please see the fixes section for patch availability.

Mandrake Linux has released advisory MDKSA-2004:090 along with fixes dealing with this issue. Please see the referenced advisory for more information.

Conectiva Linux has released advisory CLA-2004:865 along with fixes dealing with this issue. Please see the referenced advisory for more information.

Debian Woody 3.0 unstable releases were vulnerable to this issue, however, it has been addressed in version 1.2.1.1-6. Debian Woody 3.0 stable is not vulnerable to this issue.

SCO Linux has released advisory SCOSA-2004.17 along with fixes dealing with this issue. Please see the referenced advisory for more information.

Conectiva Linux has released advisory CLA-2004:878 along with fixes for their Conectiva Linux 10.0 product dealing with this issue. Please see the referenced advisory for more information.

Avaya has released an interim advisory ASA-2004-067 regarding this issue. Please see the referenced advisory for further information.

Fedora has released FEDORA-2005-095 addressing this issue for Fedora Core 2. Please see the referenced advisory for further information.

Fedora Legacy has released advisory FLSA:2043 to provide fixes for Fedora Core 1. Please see the referenced advisory for further information.

zlib version 1.2.2 has been released to address this issue.

OpenPKG has released advisory OpenPKG-SA-2005.007 to address this issue in OpenPKG 2.2 and OpenPKG 2.3. Please see the referenced advisory for more information.

SCO advisory SCOSA-2005.33 is available to address various issues affecting UnixWare 7.1.4 and UnixWare 7.1.3. Please see the referenced advisory for more information.

CVS 1.12.13 is available to address this and other issues.

Trustix has released advisory TSLSA-2005-0055 to address multiple issues. Please see the referenced advisory for more information.

SCO has released security advisory SCOSA-2006.6 to address this issue is OpenServer 5.0.6, 5.0.7 and 6.0.0. Please see the referenced advisory for further information.


CVS CVS 1.12.12

zlib zlib 1.2 .0.7

zlib zlib 1.2.1

SCO Open Server 5.0.6

SCO Open Server 5.0.7

SCO Open Server 6.0

SCO Unixware 7.1.3

SCO Unixware 7.1.4

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report