CVS Home Information for VU#680620
zlib inflate() routine vulnerable to buffer overflow
- Vendor Information Help Date Notified:
- Statement Date:
- Date Updated: 05 Oct 2005
Status
Affected
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
Vendor Information
The vendor has not provided us with any further information regarding this vulnerability.
Vendor References
None
Addendum
From the CVS version 1.12.13 NEWS file:
CVS now uses version 1.2.3 of the ZLib compression libraries in order to avoid two recently announced security vulnerabilities in them. Both may be used for denial of service attacks and one may reportedly allow execution of arbitrary code, though this is not confirmed. Please see the CERT vulnerabilities advisories #238678 <http://www.kb.cert.org/vuls/id/238678> & #680620 <http://www.kb.cert.org/vuls/id/680620> for more.
If you have feedback, comments, or additional information about this vulnerability, please send us email.