Bug 163038 - CAN-2005-1849 zlib buffer overflow
Summary: CAN-2005-1849 zlib buffer overflow
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: zlib
Version: 4
Hardware: All
OS: Linux
medium
urgent
Target Milestone: ---
Assignee: Ivana Varekova
QA Contact:
URL:
Whiteboard: public=20050820,impact=critical,sourc...
Keywords: Security
Depends On:
Blocks: CVE-2005-1849
TreeView+ depends on / blocked
 
Reported: 2005-07-12 13:50 UTC by Josh Bressers
Modified: 2008-01-29 11:01 UTC (History)
2 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2005-08-25 09:41:13 UTC


Attachments (Terms of Use)

Description Josh Bressers 2005-07-12 13:50:05 UTC
+++ This bug was initially created as a clone of Bug #163037 +++

A buffer overflow issue has been found in zlib that can overflow
inflate_state.codes[ENOUGH] by 16 bytes.

It is possible to leverage this issue by creating a valid zlib stream.

Comment 1 Josh Bressers 2005-07-12 13:51:07 UTC
This issue also affects FC3

Comment 2 Ivana Varekova 2005-07-22 11:08:47 UTC
Fixed versions are devel - zlib-1.2.2.2-5, fc4 - zlib-1.2.2.2-5.fc4
and fc3 - zlib-1.2.1.2-3.fc3

Comment 3 Walter Justen 2005-08-25 09:41:13 UTC
Thanks for the bug report. This particular bug was fixed and a update package
was published for download. Please feel free to report any further bugs you find.


Note You need to log in before you can comment on or make changes to this bug.