Advisories: July 7, 2005

Jul 08, 2005, 04:45 (0 Talkback[s])

Debian GNU/Linux

Debian Security Advisory DSA 741-1 Martin Schulze
July 7th, 2005

Package : bzip2
Vulnerability : infinite loop
Problem-Type : local (remote)
Debian-specific: no
CVE ID : CAN-2005-1260
Debian Bug : 310803

Chris Evans discovered that a specially crafted archive can trigger an infinete loop in bzip2, a high-quality block-sorting file compressor. During uncompression this results in an indefinitively growing output file which will finally fill up the disk and. On systems that automatically decompress bzip2 archives this can cause a denial of service.

For the oldstable distribution (woody) this problem has been fixed in version 1.0.2-1.woody5.

For the stable distribution (sarge) this problem has been fixed in version 1.0.2-7.

For the unstable distribution (sid) this problem has been fixed in version 1.0.2-7.

We recommend that you upgrade your bzip2 package.

Upgrade Instructions

wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody

Fedora Core

Fedora Update Notification

Product : Fedora Core 4
Name : zlib
Version :
Release : 4.fc4
Summary : The zlib compression and decompression library.

Description :
Zlib is a general-purpose, patent-free, lossless data compression library which is used by many different programs.

Update Information:

This update corrects security problem CAN-2005-2096.

  • Thu Jul 7 2005 Ivana Varekova <>
    • fix bug 162392 - CAN-2005-2096

This update can be downloaded from:

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Mandriva Linux

Mandriva Linux Security Update Advisory

Package name: zlib
Advisory ID: MDKSA-2005:112
Date: July 6th, 2005
Affected versions: 10.0, 10.1, 10.2, Corporate 3.0

Problem Description:

Tavis Ormandy of the Gentoo Security Project discovered a vulnerability in zlib where a certain data stream would cause zlib to corrupt a data structure, resulting in the linked application to dump core.

The updated packages have been patched to correct this problem.


Updated Packages:

To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver 0x22458A98

You can view other update advisories for Mandriva Linux at:

If you want to report vulnerabilities, please contact


Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*>