- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-25
- - ---------------------------------------------------------------------

          PACKAGE : zlib
          SUMMARY : buffer overrun
             DATE : 2003-03-28 10:50 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : <1.1.4-r1 : fixed version>=1.1.4-r1
              CVE : CAN-2003-0107

- - ---------------------------------------------------------------------

- From advisory:
"zlib contains a function called gzprintf().  This is similar in
behaviour to fprintf() except that by default, this function will
smash the stack if called with arguments that expand to more than
Z_PRINTF_BUFSIZE (=4096 by default) bytes."

Read the full advisory at 


SOLUTION

It is recommended that all Gentoo Linux users who are running
sys-libs/zlib upgrade to zlib-1.1.4-r1 as follows:

emerge sync
emerge zlib
emerge clean

- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - ---------------------------------------------------------------------

1.1.4-r1

Gentoo: zlib stack overflow vulnerability

The function gzprintf() is similar in behaviour to fprintf() except that by default, this function will smash the stack if called with arguments that expand to more than Z_PRINTF_B...

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200303-25
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
- From advisory: "zlib contains a function called gzprintf(). This is similar in behaviour to fprintf() except that by default, this function will smash the stack if called with arguments that expand to more than Z_PRINTF_BUFSIZE (=4096 by default) bytes."
Read the full advisory at

SOLUTION
It is recommended that all Gentoo Linux users who are running sys-libs/zlib upgrade to zlib-1.1.4-r1 as follows:
emerge sync emerge zlib emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
1.1.4-r1

Resolution

References

Availability

Concerns

Severity
PACKAGE : zlib
SUMMARY : buffer overrun
DATE : 2003-03-28 10:50 UTC
EXPLOIT : remote
VERSIONS AFFECTED : <1.1.4-r1 : fixed version>=1.1.4-r1
CVE : CAN-2003-0107

Synopsis

Background

Affected Packages

Impact

Workaround

Related News