Bug 162392
Summary: | CAN-2005-2096 zlib buffer overflow | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Josh Bressers <bressers> |
Component: | zlib | Assignee: | Ivana Varekova <varekova> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | 4 | CC: | security-response-team, sundaram |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | embargo=20050706,impact=important,source=vendorsec,reported=20060630 | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2005-09-05 06:02:58 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 162680, 430650 |
Description
Josh Bressers
2005-07-03 23:29:28 UTC
This issue should also affect FC3. Please see the parent bug for all the details. Lifting embargo Can we get some FC updates for this issue soon? There are fixed versions for devel (zlib-1.2.2.2-4), fc4 (zlib-1.2.2.2-4.fc4) and fc3 (zlib-1.2.2.2-2.fc3). Oh, mistake - fc3 version is zlib-1.2.1.2-2.fc3 Following the paper from Florian Weimer: http://www.enyo.de/fw/security/zlib-fingerprint/ and scanning an up to date FC4-install, it reported: - rsync - restore, modprobe, modinfo, depmod from FC4 to still contain a statically linked version against an old zlib. If somebody could confirm, would it be possible to please compile new releases? modprobe, modinfo, depmod have no security context (if you have a malcious kernel module you're about to load it doesn't really matter if it can exploit you by zlib). restore/dump similarly. rsync includes version 1.1.4 of zlib and is therefore unaffected by this issue. |