zlib 缓冲区溢出漏洞

漏洞信息详情

zlib 缓冲区溢出漏洞

漏洞简介

zlib是一个供其他应用程序使用的压缩库,它能够提供数据压缩/解压例程。

Zlib 1.2及其后的版本中存在缓冲区溢出漏洞。

通过特制的包含不正确的长度大于1的代码描述,将导致缓冲区溢出,攻击者可利用此漏洞导致程序崩溃。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

http://www.zlib.net/

参考网址

来源: US-CERT

名称: VU#680620

链接:http://www.kb.cert.org/vuls/id/680620

来源: BID

名称: 14162

链接:http://www.securityfocus.com/bid/14162

来源: REDHAT

名称: RHSA-2005:569

链接:http://www.redhat.com/support/errata/RHSA-2005-569.html

来源: GENTOO

名称: GLSA-200509-18

链接:http://www.gentoo.org/security/en/glsa/glsa-200509-18.xml

来源: VUPEN

名称: ADV-2005-0978

链接:http://www.frsirt.com/english/advisories/2005/0978

来源: DEBIAN

名称: DSA-797

链接:http://www.debian.org/security/2005/dsa-797

来源: DEBIAN

名称: DSA-740

链接:http://www.debian.org/security/2005/dsa-740

来源: SUNALERT

名称: 101989

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101989-1

来源: GENTOO

名称: GLSA-200507-05

链接:http://security.gentoo.org/glsa/glsa-200507-05.xml

来源: SECUNIA

名称: 15949

链接:http://secunia.com/advisories/15949

来源: FEDORA

名称: FLSA:162680

链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162680

来源: MISC

链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162391

来源: UBUNTU

名称: USN-148-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-148-1

来源: REDHAT

名称: RHSA-2008:0629

链接:http://www.redhat.com/support/errata/RHSA-2008-0629.html

来源: support.apple.com

链接:http://support.apple.com/kb/HT3298

来源: SECTRACK

名称: 1014398

链接:http://securitytracker.com/id?1014398

来源: SECUNIA

名称: 31492

链接:http://secunia.com/advisories/31492

来源: APPLE

名称: APPLE-SA-2005-08-15

链接:http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html

来源: APPLE

名称: APPLE-SA-2005-08-17

链接:http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html

来源: APPLE

名称: APPLE-SA-2008-11-13

链接:http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html

来源: FREEBSD

名称: FreeBSD-SA-05:16.zlib

链接:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:16.zlib.asc

来源: XF

名称: hpux-secure-shell-dos(24064)

链接:http://xforce.iss.net/xforce/xfdb/24064

来源: www.vmware.com

链接:http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html

来源: www.vmware.com

链接:http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html

来源: UBUNTU

名称: USN-151-3

链接:http://www.ubuntulinux.org/usn/usn-151-3

来源: BUGTRAQ

名称: 20071029 Windows binary of “Virtual Floppy Drive 2.1” contains vulnerable zlib (CAN-2005-2096)

链接:http://www.securityfocus.com/archive/1/archive/1/482950/100/0/threaded

来源: BUGTRAQ

名称: 20071029 Re: Windows binary of “GSview 4.8” contain vulnerable zlib (CAN-2005-2096)

链接:http://www.securityfocus.com/archive/1/archive/1/482949/100/0/threaded

来源: BUGTRAQ

名称: 20071021 Re: Windows binary of “GSview 4.8” contain vulnerable zlib (CAN-2005-2096)

链接:http://www.securityfocus.com/archive/1/archive/1/482601/100/0/threaded

来源: BUGTRAQ

名称: 20071020 Re: Windows binary of “GSview 4.8” contain vulnerable zlib (CAN-2005-2096)

链接:http://www.securityfocus.com/archive/1/archive/1/482571/100/0/threaded

来源: BUGTRAQ

名称: 20071018 Official Windows binaries of “curl” contain vulnerable zlib 1.2.2 (CAN-2005-2096)

链接:http://www.securityfocus.com/archive/1/archive/1/482505/100/0/threaded

来源: BUGTRAQ

名称: 20071018 Windows binary of “GSview 4.8” contain vulnerable zlib (CAN-2005-2096)

链接:http://www.securityfocus.com/archive/1/archive/1/482503/100/0/threaded

来源: BUGTRAQ

名称: 20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates

链接:http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded

来源: HP

名称: HPSBUX02090

链接:http://www.securityfocus.com/archive/1/archive/1/421411/100/0/threaded

来源: MANDRIVA

名称: MDKSA-2006:070

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:070

来源: MANDRIVA

名称: MDKSA-2005:196

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:196

来源: MANDRAKE

名称: MDKSA-2005:112

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:112

来源: VUPEN

名称: ADV-2007-1267

链接:http://www.frsirt.com/english/advisories/2007/1267

来源: VUPEN

名称: ADV-2006-0144

链接:http://www.frsirt.com/english/advisories/2006/01

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享