PT-2005-5599 · Zlib+3 · Zlib+5

Marc Deslauriers

·

Published

1970-01-01

·

Updated

2022-06-22

·

CVE-2005-1849

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions zlib version 1.2.2 qt versions prior to 3.3.4-r8 sash (affected versions not specified) lib64z1-dev (affected versions not specified) lib64z1 (affected versions not specified)
Description The issue involves multiple vulnerabilities in various packages, including zlib, qt, sash, lib64z1-dev, and lib64z1, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. In the case of zlib, a specific vulnerability in inftrees.h allows remote attackers to cause a denial of service via an invalid file. The vulnerabilities can lead to application crashes or other disruptions, affecting the security of the system.
Recommendations For zlib version 1.2.2, consider updating to a newer version to address the vulnerability. For qt versions prior to 3.3.4-r8, update to version 3.3.4-r8 or later to resolve the issue. For sash, lib64z1-dev, and lib64z1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03299
BDU:2015-03403
BDU:2015-03574
BDU:2015-03575
BDU:2015-09477
CVE-2005-1849
DSA-1026-1
DSA-763-1
DSA-797-1
RHSA-2005:584
RHSA-2005_584
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629

Affected Products

Red Hat
Lib64Z1
Lib64Z1-Dev
Qt
Sash
Zlib