LWN.net Logo

zlib corrupts malloc data structures via double free

Package(s):zlib rsync libz vnc zlib, cvs, gnupg, rrdtool, libz/zlib packages upgrade security problems cvs recompiled against updated + /tmp CVE #(s):CAN-2002-0059 CAN-2002-0092 CAN-2002-0080
Created:May 21, 2002 Updated:June 6, 2002
Description: This vulnerability impacts all major Linux vendors. It may impact every Linux installation on Earth. Updates are required to zlib and any packages that were statically built with the zlib code. (First LWN report: March 14).

LinuxSecurity describes the vulnerability and coordinated distributor efforts in detail. "Packages including X11, rsync, the Linux kernel, QT, mozilla, gcc, vnc, and many other programs that have the ability to use network compression are potentially vulnerable."

Updating is recommended. As always, please proceed with caution when applying updates to the kernel.

Alerts:
Conectiva CLA-2002:493 2002-06-05
Trustix 2002-0040 2002-03-18
SuSE SuSE-SA:2002:011 2002-03-11
SuSE SuSE-SA:2002:010 2002-03-11
Slackware sl-1015950525 2002-03-12
Slackware sl-1015949806 2002-03-12
Red Hat RHSA-2002:027-22 2002-03-11
Red Hat RHSA-2002:026-39 2002-03-15
Red Hat RHSA-2002:026-35 2002-03-11
OpenPKG OpenPKG-SA-2002.003 2002-03-12
Mandrake MDKSA-2002:023-1 2002-03-13
Mandrake MDKSA-2002:023 2002-03-12
Mandrake MDKSA-2002:022 2002-03-12
Eridani ERISA-2002:009 2002-03-13
Eridani ERISA-2002:008 2002-03-13
Debian DSA-122-1 2002-03-11
SCO Group CSSA-2002-015.0 2002-04-04

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds