Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53398
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 122-1 (zlib, various)
Summary:The remote host is missing an update to zlib, various;announced via advisory DSA 122-1.
Description:Summary:
The remote host is missing an update to zlib, various
announced via advisory DSA 122-1.

Vulnerability Insight:
The compression library zlib has a flaw in which it attempts to free
memory more than once under certain conditions. This can possibly be
exploited to run arbitrary code in a program that includes zlib. If a
network application running as root is linked to zlib, this could
potentially lead to a remote root compromise. No exploits are known at
this time. This vulnerability is assigned the CVE candidate name of
CVE-2002-0059.

The zlib vulnerability is fixed in the Debian zlib package version
1.1.3-5.1. A number of programs either link statically to zlib or include
a private copy of zlib code. These programs must also be upgraded
to eliminate the zlib vulnerability. The affected packages and fixed
versions follow:
amaya 2.4-1potato1
dictd 1.4.9-9potato1
erlang 49.1-10.1
freeamp 2.0.6-2.1
mirrordir 0.10.48-2.1
ppp 2.3.11-1.5
rsync 2.3.2-1.6
vrweb 1.5-5.1

Those using the pre-release (testing) version of Debian should upgrade
to zlib 1.1.3-19.1 or a later version. Note that since this version of
Debian has not yet been released it may not be available immediately for
all architectures. Debian 2.2 (potato) is the latest supported release.

Solution:
We recommend that you upgrade your packages immediately. Note that you

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-0059
BugTraq ID: 4267
http://www.securityfocus.com/bid/4267
Bugtraq: 20020311 security problem fixed in zlib 1.1.4 (Google Search)
Bugtraq: 20020312 Re: [VulnWatch] exploiting the zlib bug in openssh (Google Search)
Bugtraq: 20020312 [OpenPKG-SA-2002.003] OpenPKG Security Advisory (zlib) (Google Search)
Bugtraq: 20020312 exploiting the zlib bug in openssh (Google Search)
Bugtraq: 20020312 zlib & java (Google Search)
Bugtraq: 20020312 zlibscan : script to find suid binaries possibly affected by zlib vulnerability (Google Search)
Bugtraq: 20020313 OpenSSH rebuild warning: problems avoiding zlib problems in Solaris (Google Search)
Bugtraq: 20020314 Re: about zlib vulnerability - Microsoft products (Google Search)
Bugtraq: 20020314 ZLib double free bug: Windows NT potentially unaffected (Google Search)
Bugtraq: 20020314 about zlib vulnerability (Google Search)
Bugtraq: 20020315 RE: [Whitehat] about zlib vulnerability (Google Search)
Bugtraq: 20020318 TSLSA-2002-0040 - zlib (Google Search)
Bugtraq: 20020402 VNC Security Bulletin - zlib double free issue (multiple vendors and versions) (Google Search)
http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txt
Caldera Security Advisory: CSSA-2002-015.1
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-015.1.txt
http://www.cert.org/advisories/CA-2002-07.html
CERT/CC vulnerability note: VU#368819
http://www.kb.cert.org/vuls/id/368819
Cisco Security Advisory: 20020403 Vulnerability in the zlib Compression Library
Conectiva Linux advisory: CLA-2002:469
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000469
Debian Security Information: DSA-122 (Google Search)
http://www.debian.org/security/2002/dsa-122
En Garde Linux Advisory: ESA-20020311-008
FreeBSD Security Advisory: FreeBSD-SA-02:18
HPdes Security Advisory: HPSBTL0204-030
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-030
HPdes Security Advisory: HPSBTL0204-036
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-036
HPdes Security Advisory: HPSBTL0204-037
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-037
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:022
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-023.php
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3
OpenBSD Security Advisory: 20020313 015: RELIABILITY FIX: March 13, 2002
http://www.redhat.com/support/errata/RHSA-2002-026.html
http://www.redhat.com/support/errata/RHSA-2002-027.html
SuSE Security Announcement: SuSE-SA:2002:010 (Google Search)
SuSE Security Announcement: SuSE-SA:2002:011 (Google Search)
XForce ISS Database: zlib-doublefree-memory-corruption(8427)
https://exchange.xforce.ibmcloud.com/vulnerabilities/8427
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.