PT-2005-5600 · Zlib+4 · Zlib-Devel+6
Matthew Miller
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2005-2096
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
zlib versions 1.2 and later
zsync (affected versions not specified)
sash (affected versions not specified)
zlib-devel (affected versions not specified)
zlib-devel-32bit (affected versions not specified)
Description
The issue allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow. This can be demonstrated using a crafted PNG file. The exploitation of these vulnerabilities may lead to a disruption of confidentiality, integrity, and availability of protected information.
Recommendations
For zlib versions 1.2 and later, consider updating to a version that fixes the buffer overflow issue.
For zsync, sash, zlib-devel, and zlib-devel-32bit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Png
Red Hat
Sash
Zlib
Zlib-Devel
Zlib-Devel-32Bit
Zsync