PT-2009-3906 · Unknown · Compress::Raw::Zlib

Leo Bergolth

·

Published

2009-06-16

·

Updated

2018-10-03

·

CVE-2009-1391

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Compress::Raw::Zlib versions prior to 2.017
Description The issue is related to an off-by-one error in the inflate function in Zlib.xs, which can be exploited by context-dependent attackers to cause a denial of service, resulting in a hang or crash. This is achieved through a crafted zlib compressed stream that triggers a heap-based buffer overflow. The issue has been exploited in the wild, for example, by Trojan.Downloader-71014 in June 2009.
Recommendations For versions prior to 2.017, update to version 2.017 or later to resolve the issue. As a temporary workaround, consider restricting the use of the inflate function in Zlib.xs to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1391

Affected Products

Compress::Raw::Zlib