ZLib Compression Library Heap Corruption Vulnerability

BID:4267

Info

ZLib Compression Library Heap Corruption Vulnerability

Bugtraq ID: 4267
Class: Design Error
CVE: CVE-2002-0059
Remote: Yes
Local: Yes
Published: Mar 11 2002 12:00AM
Updated: Oct 24 2007 04:37AM
Credit: Credited to Mark J Cox <[email protected]>, Matthias Clasen <[email protected]>, Owen Taylor <[email protected]>.
Vulnerable: zlib zlib 1.1.3
zlib zlib 1.1.2
zlib zlib 1.1.1
zlib zlib 1.1
zlib zlib 1.0.9
zlib zlib 1.0.8
zlib zlib 1.0.7
zlib zlib 1.0.6
zlib zlib 1.0.5
zlib zlib 1.0.4
- XFree86 X11R6 3.3.6
- XFree86 X11R6 3.3.5
- XFree86 X11R6 3.3.4
- XFree86 X11R6 3.3.3
- XFree86 X11R6 3.3.2
- XFree86 X11R6 3.3
zlib zlib 1.0.3
zlib zlib 1.0.2
zlib zlib 1.0.1
zlib zlib 1.0
Sun SunOS 5.8 _x86
Sun SunOS 5.8
Sun SDK (Windows Production Release) 1.4
Sun SDK (Windows Production Release) 1.3.1 _03
Sun SDK (Windows Production Release) 1.3 .0_05
Sun SDK (Windows Production Release) 1.2.2 _011
Sun SDK (Solaris Reference Release) 1.2.2 _011
Sun SDK (Solaris Production Release) 1.4
Sun SDK (Solaris Production Release) 1.3.1 _03
Sun SDK (Solaris Production Release) 1.3 _05
Sun SDK (Solaris Production Release) 1.2.2 _011
Sun SDK (Linux Production Release) 1.4
Sun SDK (Linux Production Release) 1.3.1 _03
Sun SDK (Linux Production Release) 1.3 _05
Sun SDK (Linux Production Release) 1.2.2 _011
Sun OpenWindows 3.6.2
Sun OpenWindows 3.6.1
Sun JRE (Windows Production Release) 1.4
Sun JRE (Windows Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Windows Production Release) 1.3 .0_05
Sun JRE (Windows Production Release) 1.2.2 _011
Sun JRE (Windows Production Release) 1.1.8 _009
Sun JRE (Solaris Reference Release) 1.2.2 _011
Sun JRE (Solaris Reference Release) 1.1.8 _099
Sun JRE (Solaris Production Release) 1.4
Sun JRE (Solaris Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Solaris Production Release) 1.3 .0_05
Sun JRE (Solaris Production Release) 1.2.2 _011
Sun JRE (Solaris Production Release) 1.1.8 _009
Sun JRE (Linux Production Release) 1.4
Sun JRE (Linux Production Release) 1.3.1 _03
Sun JRE (Linux Production Release) 1.3 .0_05
Sun JRE (Linux Production Release) 1.2.2 _011
Sun JDK (Windows Production Release) 1.1.8 _009
Sun JDK (Solaris Reference Release) 1.1.8 _099
Sun JDK (Solaris Production Release) 1.1.8 _009
Sun JDK (Linux Production Release) 1.1.8 _09
Softwin BitDefender 8.0
Softwin BitDefender 7.2
Softwin BitDefender 10.0
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
SGI IRIX 6.5.14 m
SGI IRIX 6.5.14 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
Rit Research Labs The Bat! 2.0 3 Beta
Rit Research Labs The Bat! 2.0 1
Rit Research Labs The Bat! 2.0
Rit Research Labs The Bat! 1.101
Rit Research Labs The Bat! 1.53 d
Rit Research Labs The Bat! 1.52
Rit Research Labs The Bat! 1.51
Rit Research Labs The Bat! 1.49
Rit Research Labs The Bat! 1.48
Rit Research Labs The Bat! 1.47
Rit Research Labs The Bat! 1.46
Rit Research Labs The Bat! 1.45
Rit Research Labs The Bat! 1.44
Rit Research Labs The Bat! 1.43
Rit Research Labs The Bat! 1.42 f
Rit Research Labs The Bat! 1.42
Rit Research Labs The Bat! 1.41
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Rit Research Labs The Bat! 1.39
Rit Research Labs The Bat! 1.36
Rit Research Labs The Bat! 1.35
Rit Research Labs The Bat! 1.34
Rit Research Labs The Bat! 1.33
Rit Research Labs The Bat! 1.32
Rit Research Labs The Bat! 1.31
Rit Research Labs The Bat! 1.22
Rit Research Labs The Bat! 1.21
Rit Research Labs The Bat! 1.19
Rit Research Labs The Bat! 1.18
Rit Research Labs The Bat! 1.17
Rit Research Labs The Bat! 1.15
Rit Research Labs The Bat! 1.14
Rit Research Labs The Bat! 1.5
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
Rit Research Labs The Bat! 1.1
Rit Research Labs The Bat! 1.0 43
Rit Research Labs The Bat! 1.0 41
Rit Research Labs The Bat! 1.0 39
Rit Research Labs The Bat! 1.0 37
Rit Research Labs The Bat! 1.0 36
Rit Research Labs The Bat! 1.0 35
Rit Research Labs The Bat! 1.0 32
Rit Research Labs The Bat! 1.0 31
Rit Research Labs The Bat! 1.0 29
Rit Research Labs The Bat! 1.0 28
Rit Research Labs The Bat! 1.0 15
Rit Research Labs The Bat! 1.0 11
Rit Research Labs The Bat! 1.0 build 1349
Rit Research Labs The Bat! 1.0 build 1336
RealNetworks RealSystem Proxy 8.0
RealNetworks Real Server 8.0
RealNetworks Real Server 7.0.2
RealNetworks Real Server 7.0.1
RealNetworks Real Server 7.0
RealNetworks Real Server 6.0 x
RealNetworks Helix Universal Server 9.0
RealNetworks Helix Universal Proxy 9.0
RealNetworks Helix Universal Gateway 9.0
Macromedia Flash 6.0.47 .0
Macromedia Flash 6.0
+ Microsoft Internet Explorer 5.0.1 SP2
+ Microsoft Internet Explorer 5.0.1 SP2
+ Microsoft Internet Explorer 5.0.1 SP1
+ Microsoft Internet Explorer 5.0.1 SP1
+ Microsoft Internet Explorer 5.0.1
+ Microsoft Internet Explorer 5.0.1
+ Microsoft Internet Explorer 6.0
+ Microsoft Internet Explorer 6.0
+ Microsoft Internet Explorer 5.5 SP2
+ Microsoft Internet Explorer 5.5 SP2
+ Microsoft Internet Explorer 5.5 SP1
+ Microsoft Internet Explorer 5.5 SP1
+ Microsoft Internet Explorer 5.5 preview
+ Microsoft Internet Explorer 5.5 preview
+ Microsoft Internet Explorer 5.5
+ Microsoft Internet Explorer 5.5
+ Microsoft Internet Explorer 5.0
+ Microsoft Internet Explorer 5.0
+ Microsoft Windows XP Embedded SP3
+ Microsoft Windows XP Embedded SP2
+ Microsoft Windows XP Home SP3
+ Microsoft Windows XP Home SP2
+ Microsoft Windows XP Media Center Edition SP3
+ Microsoft Windows XP Media Center Edition SP2
+ Microsoft Windows XP Professional SP3
+ Microsoft Windows XP Professional SP2
+ Microsoft Windows XP Professional x64 Edition SP2
+ Microsoft Windows XP Tablet PC Edition SP3
+ Microsoft Windows XP Tablet PC Edition SP2
+ Netscape Communicator 6.1
+ Netscape Communicator 6.1
+ Netscape Communicator 4.78
+ Netscape Communicator 4.78
+ Netscape Communicator 4.77
+ Netscape Communicator 4.77
+ Netscape Communicator 4.76
+ Netscape Communicator 4.76
+ Netscape Communicator 4.75
+ Netscape Communicator 4.75
+ Netscape Communicator 4.74
+ Netscape Communicator 4.74
+ Netscape Communicator 4.73
+ Netscape Communicator 4.73
+ Netscape Communicator 4.72
+ Netscape Communicator 4.72
+ Netscape Communicator 4.61
+ Netscape Communicator 4.61
+ Netscape Communicator 4.51
+ Netscape Communicator 4.51
+ Netscape Communicator 4.7
+ Netscape Communicator 4.7
+ Netscape Communicator 4.6
+ Netscape Communicator 4.6
+ Redhat netscape-common-4.76-11.i386.rpm
+ Redhat netscape-common-4.78-2.i386.rpm
+ Redhat netscape-common-4.79-1.i386.rpm
+ Redhat netscape-communicator-4.76-11.i386.rpm
+ Redhat netscape-communicator-4.78-2.i386.rpm
+ Redhat netscape-communicator-4.79-1.i386.rpm
+ Redhat netscape-navigator-4.76-11.i386.rpm
+ Redhat netscape-navigator-4.78-2.i386.rpm
+ Redhat netscape-navigator-4.79-1.i386.rpm
Macromedia Flash 5.0
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows 95 SR2
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
HP Secure OS software for Linux 1.0
GNOME Gnome 2.0
Compaq Tru64 5.1 a PK3 (BL3)
Compaq Tru64 5.1 a
Compaq Tru64 5.1
Cisco Metro 1500 DWDM
Cisco ME1100
Cisco IDS-4230-xx
Cisco IDS-4220-E
Cisco IDS-4210
Cisco Hosting Solution Engine 1.3
Cisco Hosting Solution Engine 1.0
Cisco Content Router 4430
Cisco Content Engine 7320
Cisco Content Engine 590
Cisco Content Engine 560
Cisco Content Engine 507
Cisco Content Distribution Manager 4650
Cisco Content Distribution Manager 4630
Cisco Catalyst 6000 IDS Module
Not Vulnerable: zlib zlib 1.1.4
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ GLT GLT 0.6
+ NetBSD NetBSD 1.6
+ NetBSD NetBSD 1.5.3
+ NetBSD NetBSD 1.5.2
+ NetBSD NetBSD 1.5.1
+ NetBSD NetBSD 1.5
- NullSoft Winamp 2.79
+ OpenPKG OpenPKG 1.2
+ OpenPKG OpenPKG 1.1
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Linux Advanced Work Station 2.1
+ Sun Cobalt Qube 3
+ Sun Cobalt Qube3 4000WG
+ Sun Cobalt Qube3 Japanese 4000WGJ
+ Sun Cobalt Qube3 Japanese w/ Caching and RAID 4100WGJ
+ Sun Cobalt Qube3 Japanese w/Caching 4010WGJ
+ Sun Cobalt Qube3 w/ Caching and RAID 4100WG
+ Sun Cobalt Qube3 w/Caching 4010WG
+ Sun Cobalt RaQ 4
+ Sun Cobalt RaQ XTR
+ Sun Cobalt RaQ XTR 3500R
+ Sun Cobalt RaQ XTR Japanese 3500R-ja
+ Sun Cobalt RaQ4 3001R
+ Sun Cobalt RaQ4 Japanese RAID 3100R-ja
+ Sun Cobalt RaQ4 RAID 3100R
+ Sun Linux 5.0
Sun Java 2 Standard Edition SDK 1.4.1
SGI IRIX 6.5.18
Macromedia Flash 6.0
+ Microsoft Internet Explorer 5.0.1 SP2
+ Microsoft Internet Explorer 5.0.1 SP2
+ Microsoft Internet Explorer 5.0.1 SP1
+ Microsoft Internet Explorer 5.0.1 SP1
+ Microsoft Internet Explorer 5.0.1
+ Microsoft Internet Explorer 5.0.1
+ Microsoft Internet Explorer 6.0
+ Microsoft Internet Explorer 6.0
+ Microsoft Internet Explorer 5.5 SP2
+ Microsoft Internet Explorer 5.5 SP2
+ Microsoft Internet Explorer 5.5 SP1
+ Microsoft Internet Explorer 5.5 SP1
+ Microsoft Internet Explorer 5.5 preview
+ Microsoft Internet Explorer 5.5 preview
+ Microsoft Internet Explorer 5.5
+ Microsoft Internet Explorer 5.5
+ Microsoft Internet Explorer 5.0
+ Microsoft Internet Explorer 5.0
+ Microsoft Windows XP Embedded SP3
+ Microsoft Windows XP Embedded SP2
+ Microsoft Windows XP Home SP3
+ Microsoft Windows XP Home SP2
+ Microsoft Windows XP Media Center Edition SP3
+ Microsoft Windows XP Media Center Edition SP2
+ Microsoft Windows XP Professional SP3
+ Microsoft Windows XP Professional SP2
+ Microsoft Windows XP Professional x64 Edition SP2
+ Microsoft Windows XP Tablet PC Edition SP3
+ Microsoft Windows XP Tablet PC Edition SP2
+ Netscape Communicator 6.1
+ Netscape Communicator 6.1
+ Netscape Communicator 4.78
+ Netscape Communicator 4.78
+ Netscape Communicator 4.77
+ Netscape Communicator 4.77
+ Netscape Communicator 4.76
+ Netscape Communicator 4.76
+ Netscape Communicator 4.75
+ Netscape Communicator 4.75
+ Netscape Communicator 4.74
+ Netscape Communicator 4.74
+ Netscape Communicator 4.73
+ Netscape Communicator 4.73
+ Netscape Communicator 4.72
+ Netscape Communicator 4.72
+ Netscape Communicator 4.61
+ Netscape Communicator 4.61
+ Netscape Communicator 4.51
+ Netscape Communicator 4.51
+ Netscape Communicator 4.7
+ Netscape Communicator 4.7
+ Netscape Communicator 4.6
+ Netscape Communicator 4.6
+ Redhat netscape-common-4.76-11.i386.rpm
+ Redhat netscape-common-4.78-2.i386.rpm
+ Redhat netscape-common-4.79-1.i386.rpm
+ Redhat netscape-communicator-4.76-11.i386.rpm
+ Redhat netscape-communicator-4.78-2.i386.rpm
+ Redhat netscape-communicator-4.79-1.i386.rpm
+ Redhat netscape-navigator-4.76-11.i386.rpm
+ Redhat netscape-navigator-4.78-2.i386.rpm
+ Redhat netscape-navigator-4.79-1.i386.rpm
Compaq Tru64 5.0 a
Compaq Tru64 5.0
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f

Discussion

ZLib Compression Library Heap Corruption Vulnerability

The 'zlib' compression library is prone to a heap-corruption vulnerability.

Under some circumstances, a block of dynamically allocated memory may have the 'free()' routine called on it twice. This may occur during decompression.

An exploitable condition may result if the 'free()' function is used on memory that has already been freed. Under some circumstances, an attacker may be able to manipulate data layout in the heap so that an arbitrary word in memory is overwritten with a custom value when 'free()' is called for the second time.

Arbitrary code may run if critical values such as function return addresses, GOT entries, etc., are overwritten.

By itself, this condition is not a vulnerability. An attacker must identify a program that is linked to the library or that uses vulnerable code with higher privileges (e.g. installed setuid) or runs on a remote machine. The attacker must also locate a method through which the condition may be triggered (for example, by supplying compressed data as input).

Several programs use 'zlib' or vulnerable code borrowed from the library, including:

SSH / OpenSSH
rsync
OpenPKG
popt / rpm
the Linux Kernel

Note that a similar vulnerability was reported in LBNL Traceroute. It was generally believed that this condition was not exploitable until proof-of-concept exploits were posted by two independent security researchers.

The FreeS/WAN IPSEC implementation reportedly also includes code from the vulnerable library. However, there are indications that this may not be exploitable in FreeS/WAN IPSEC implementations.

F-Secure SSH is not affected by this vulnerability. Apple Mac OS X is not prone to this issue.

A number of Microsoft Windows applications incorporate code from the zlib library, including Microsoft Office, Internet Explorer, DirectX, Messenger, and Front Page. It is not currently known whether these applications are affected by this issue. If they are affected, the degree of vulnerability has not been determined.

Various VNC viewer implementations may circumstantially be affected by this issue. In particular, a VNC server may be able to exploit this issue to cause a denial of service to a VNC viewer/client. TightVNC and VNCThing are known to use vulnerable versions of the compression library. VNCThing runs on MacOS operating systems and is therefore not exploitable. TridiaVNC, VNC Viewer for Java, and VNC Viewer and Server for Apple Newton are also reportedly affected.

A number of Cisco products include code from the vulnerable compression library and are thus affected by this issue. These products include:

- Cisco Content Engine 507, 560, 590, and 7320 running Cache Software 3.1.1 or Application and Content Networking Software 4.0.x or 4.1.1.

- Cisco Content Router 4430 and Content Distribution Manager 4630 and 4650 running Application and Content Networking Software 4.0.x or 4.1.1.

- Cisco ME1100.

- Cisco IDS sensor appliances IDS-4210, IDS-4220-E and IDS-4230-xx are vulnerable if the sensor version is in the range 3.0(1) through 3.0(5).

- Cisco Metro 1500 DWDM running software releases prior to 3.3b.

- Cisco Hosting Solution Engine releases 1.0 and 1.3.

Versions prior to Nullsoft Winamp 2.79 also ship with the vulnerable compression library.

While this condition may not lead to code execution on FreeBSD operating systems, it may potentially cause a denial of service in applications that use the zlib compression library.

Macromedia Flash 5 is vulnerable to this issue. It is not yet known whether earlier versions are also affected.

Exploit / POC

ZLib Compression Library Heap Corruption Vulnerability

Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report