PT-2005-5599 · Zlib+3 · Zlib+5
Marc Deslauriers
·
Published
1970-01-01
·
Updated
2022-06-22
·
CVE-2005-1849
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
zlib version 1.2.2
qt versions prior to 3.3.4-r8
sash (affected versions not specified)
lib64z1-dev (affected versions not specified)
lib64z1 (affected versions not specified)
Description
The issue involves multiple vulnerabilities in various packages, including zlib, qt, sash, lib64z1-dev, and lib64z1, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. In the case of zlib, a specific vulnerability in inftrees.h allows remote attackers to cause a denial of service via an invalid file. The vulnerabilities can lead to application crashes or other disruptions, affecting the security of the system.
Recommendations
For zlib version 1.2.2, consider updating to a newer version to address the vulnerability.
For qt versions prior to 3.3.4-r8, update to version 3.3.4-r8 or later to resolve the issue.
For sash, lib64z1-dev, and lib64z1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Lib64Z1
Lib64Z1-Dev
Qt
Sash
Zlib