zlib Buffer Overflow in 'inftrees.c' Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1014540
|
|
SecurityTracker URL: http://securitytracker.com/id?1014540
|
|
CVE Reference: CVE-2005-1849
(Links to External Site)
|
Updated: Jun 15 2008
|
Original Entry Date: Jul 21 2005
|
Impact: Denial of service via local system, Denial of service via network
|
Version(s): 1.2.2
|
Description: A vulnerability was reported in zlib. A remote user may be able to cause denial of service conditions.
The zlib library contains a buffer overflow that can be triggered when opening an invalid file, potentially causing the affected application to crash.
Markus Oberhumer is credited with discovering this vulnerability.
|
Impact: A remote or local user may be able to cause an affected application to crash.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.zlib.org/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 21 Jul 2005 03:00:35 -0400
Subject: [none]
|
Debian reported:
CAN-2005-1849
Markus Oberhumer discovered a flaw in the way zlib, a library used for
file compression and decompression, handles invalid input. This flaw can
cause programs which use zlib to crash when opening an invalid file.
|
|