|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
 |
Vulnerability Note VU#680620
zlib inflate() routine vulnerable to buffer overflow
OverviewA buffer overflow in the zlib compression library may cause any application linked to zlib to improperly and immediately terminate.
I. DescriptionThere is a buffer overflow in the zlib data-compression library caused by a lack of bounds checking in the inflate() routine. If an attacker supplies the inflate()routine with a specially crafted compressed data stream, that attacker may be able to trigger the buffer overflow causing any application linked to zlib, or incorporating zlib code to crash. According to reports, the buffer overflow is caused by a specific input stream and results in a constant value being written into an arbitrary memory location. This vulnerability may be exploited locally or remotely depending on the application being attacked.
This vulnerability only affects zlib versions 1.2.1 and 1.2.2.
II. ImpactA remote attacker be able to exploit this vulnerability by supplying the inflate() routine with specially crafted compressed data. As a result, applications linked to the zlib library may abruptly and abnormally terminate resulting in a denial-of-service condition. According to public reports, this vulnerability can be exploited to execute arbitrary code, but we have not confirmed this.
III. SolutionApply patches from your vendor
The zlib compression library is freely available and used by many vendors in a wide variety of applications. As a result, any one of these applications may contain this vulnerabilitiy. Users are encouraged to contact their vendors to determine if they are vulnerable and what action to take.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| 3Com | Unknown | 11-Jul-2005 |
| Alcatel | Unknown | 11-Jul-2005 |
| Apple Computer, Inc. | Unknown | 11-Jul-2005 |
| AT&T | Unknown | 11-Jul-2005 |
| Avaya | Unknown | 11-Jul-2005 |
| Avici Systems Inc. | Unknown | 11-Jul-2005 |
| Borderware | Unknown | 11-Jul-2005 |
| Check Point | Unknown | 11-Jul-2005 |
| Chiaro Networks | Unknown | 11-Jul-2005 |
| Cisco Systems, Inc. | Unknown | 11-Jul-2005 |
| Cisco Systems, Inc. | Unknown | 31-Aug-2005 |
| Clavister | Unknown | 11-Jul-2005 |
| Computer Associates | Unknown | 11-Jul-2005 |
| Cray Inc. | Unknown | 11-Jul-2005 |
| CVS Home | Vulnerable | 5-Oct-2005 |
| Cwnt | Unknown | 11-Jul-2005 |
| Data Connection | Unknown | 11-Jul-2005 |
| Debian Linux | Unknown | 11-Jul-2005 |
| EMC Corporation | Unknown | 11-Jul-2005 |
| Engarde | Unknown | 11-Jul-2005 |
| eSoft | Unknown | 11-Jul-2005 |
| Extreme Networks | Unknown | 11-Jul-2005 |
| F5 Networks, Inc. | Unknown | 11-Jul-2005 |
| Force10 Networks Inc. | Unknown | 11-Jul-2005 |
| Fortinet | Unknown | 11-Jul-2005 |
| Foundry Networks Inc. | Not Vulnerable | 13-Jul-2005 |
| FreeBSD, Inc. | Unknown | 11-Jul-2005 |
| Fujitsu | Unknown | 11-Jul-2005 |
| Gentoo | Vulnerable | 13-Jul-2005 |
| GTA | Unknown | 11-Jul-2005 |
| Hewlett-Packard Company | Unknown | 11-Jul-2005 |
| Hitachi | Unknown | 11-Jul-2005 |
| Hyperchip | Unknown | 11-Jul-2005 |
| IBM-zSeries | Unknown | 11-Jul-2005 |
| IBM Corporation | Unknown | 9-Aug-2005 |
| IBM eServer | Unknown | 11-Jul-2005 |
| Immunix | Unknown | 11-Jul-2005 |
| Ingrian Networks, Inc. | Unknown | 11-Jul-2005 |
| Inoto | Unknown | 11-Jul-2005 |
| Intel | Unknown | 11-Jul-2005 |
| IPf | Unknown | 11-Jul-2005 |
| ISS | Unknown | 11-Jul-2005 |
| Juniper Networks, Inc. | Not Vulnerable | 22-Jul-2005 |
| Linksys | Unknown | 11-Jul-2005 |
| Lucent Technologies | Unknown | 11-Jul-2005 |
| Luminous | Unknown | 11-Jul-2005 |
| Mandriva, Inc. | Vulnerable | 11-Jul-2005 |
| Mandriva, Inc. | Unknown | 11-Jul-2005 |
| Microsoft Corporation | Not Vulnerable | 12-Jul-2005 |
| MontaVista Software, Inc. | Unknown | 11-Jul-2005 |
| Multi-Tech Systems Inc. | Unknown | 11-Jul-2005 |
| Multinet | Unknown | 11-Jul-2005 |
| NEC Corporation | Unknown | 11-Jul-2005 |
| NetBSD | Not Vulnerable | 11-Jul-2005 |
| Netfilter | Unknown | 11-Jul-2005 |
| Network Appliance | Unknown | 11-Jul-2005 |
| NextHop | Unknown | 11-Jul-2005 |
| Nortel Networks, Inc. | Unknown | 11-Jul-2005 |
| Novell, Inc. | Unknown | 11-Jul-2005 |
| OpenBSD | Unknown | 11-Jul-2005 |
| Openwall GNU/*/Linux | Not Vulnerable | 12-Jul-2005 |
| QNX | Unknown | 11-Jul-2005 |
| Red Hat, Inc. | Vulnerable | 11-Jul-2005 |
| Redback Networks Inc. | Unknown | 11-Jul-2005 |
| Riverstone Networks | Unknown | 11-Jul-2005 |
| Secure Computing Corporation | Unknown | 11-Jul-2005 |
| SecureWorks | Unknown | 11-Jul-2005 |
| Sequent Computer Systems, Inc. | Unknown | 11-Jul-2005 |
| SGI | Unknown | 11-Jul-2005 |
| Sony Corporation | Unknown | 11-Jul-2005 |
| Stonesoft | Unknown | 11-Jul-2005 |
| Sun Microsystems, Inc. | Unknown | 11-Jul-2005 |
| SUSE Linux | Unknown | 11-Jul-2005 |
| Symantec Corporation | Unknown | 11-Jul-2005 |
| The SCO Group (SCO Linux) | Unknown | 11-Jul-2005 |
| The SCO Group (SCO Unix) | Unknown | 11-Jul-2005 |
| TurboLinux | Not Vulnerable | 12-Jul-2005 |
| Unisys | Unknown | 11-Jul-2005 |
| WatchGuard | Unknown | 11-Jul-2005 |
| Wind River Systems, Inc. | Unknown | 11-Jul-2005 |
| Zlib.org | Unknown | 11-Jul-2005 |
| ZyXEL | Unknown | 11-Jul-2005 |
References
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:16.zlib.asc
https://rhn.redhat.com/errata/RHSA-2005-569.html
http://secunia.com/advisories/15949/
http://dev.gentoo.org/~taviso/blog/#e2005-07-21T17_24_15.txt
http://secunia.com/advisories/24788
http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=3616065
http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=9916286
Credit
This vulnerability was reported by Mark Adler.
This document was written by Jeff Gennari.
Other Information
| Date Public: | 2005-07-02 |
| Date First Published: | 2005-07-12 |
| Date Last Updated: | 2007-04-05 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2005-2096 |
| NVD-ID(s): | CVE-2005-2096 |
| US-CERT Technical Alerts: | |
| Metric: | 9.45 |
| Document Revision: | 82 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|