Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA 122-1 Critical: zlib Remote Code Execution Risk

debian
Calendar Grey March 11, 2002
Debian Logo
Debian's Security Advisory DSA 122-1 indicates a critical zlib code execution risk that requires immediate upgrade.
The compression library zlib has a flaw in which it attempts to freememory more than once under certain conditions

Summary

The compression library zlib has a flaw in which it attempts to free
memory more than once under certain conditions. This can possibly be
exploited to run arbitrary code in a program that includes zlib. If a
network application running as root is linked to zlib, this could
potentially lead to a remote root compromise. No exploits are known at
this time. This vulnerability is assigned the CVE candidate name of
CAN-2002-0059.

The zlib vulnerability is fixed in the Debian zlib package version
1.1.3-5.1. A number of programs either link statically to zlib or include
a private copy of zlib code. These programs must also be upgraded
to eliminate the zlib vulnerability. The affected packages and fixed
versions follow:
amaya 2.4-1potato1
dictd 1.4.9-9potato1
erlang 49.1-10.1
freeamp 2.0.6-2.1
mirrordir 0.10.48-2.1
ppp 2.3.11-1.5
rsync 2.3.2-1.6
vrweb 1.5-5.1

Those using the pre-release (testing) version of Debian should upgrade
to zlib 1.1.3-19.1 or a later version. Note that since this version of
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: zlib, various

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here