PT-2005-5600 · Zlib+4 · Zlib-Devel+6

Matthew Miller

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2005-2096

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zlib versions 1.2 and later zsync (affected versions not specified) sash (affected versions not specified) zlib-devel (affected versions not specified) zlib-devel-32bit (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow. This can be demonstrated using a crafted PNG file. The exploitation of these vulnerabilities may lead to a disruption of confidentiality, integrity, and availability of protected information.
Recommendations For zlib versions 1.2 and later, consider updating to a version that fixes the buffer overflow issue. For zsync, sash, zlib-devel, and zlib-devel-32bit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03299
BDU:2015-03403
BDU:2015-04809
BDU:2015-04810
CVE-2005-2096
DSA-1026-1
DSA-740-1
DSA-797-1
OPENSUSE-SU-2024:10580-1
RHSA-2005:569
RHSA-2005_569
RHSA-2008:0264
RHSA-2008:0525
RHSA-2008:0629

Affected Products

Png
Red Hat
Sash
Zlib
Zlib-Devel
Zlib-Devel-32Bit
Zsync