[ Thanks to SOT Linux
Security Team for this link. ]
---------------------------------------------------------------------
SOT Linux Security Advisory
Subject: Updated zlib package for SOT Linux 2002
Advisory ID: SLSA-2003:21
Date: Monday, May 5, 2003
Product: SOT Linux 2002
---------------------------------------------------------------------
1. Problem description
Zlib is a general-purpose, patent-free, lossless data compression
library used by many different programs.
The function gzprintf within zlib, when called with a string longer than
Z_PRINTF_BUFZISE (= 4096 bytes), can overflow without giving a warning.
zlib-1.1.4 and earlier exhibit this behavior. There are no known exploits
of the gzprintf overrun, and only a few programs, including rpm2html
and gimp-print, are known to use the gzprintf function.
The problem has been fixed by checking the length of the output string
within gzprintf.
2. Updated packages
SOT Linux 2002 Desktop:
i386:
ftp://ftp.sot.com/updates/2002/Desktop/i386/zlib-1.1.4-2.i386.rpm
SRPMS:
ftp://ftp.sot.com/updates/2002/Desktop/SRPMS/zlib-1.1.4-2.src.rpm
SOT Linux 2002 Server:
i386:
ftp://ftp.sot.com/updates/2002/Server/i386/zlib-1.1.4-2.i386.rpm
SRPMS:
ftp://ftp.sot.com/updates/2002/Server/SRPMS/zlib-1.1.4-2.src.rpm
3. Upgrading package
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
Use up2date to automatically upgrade the fixed packages.
If you want to upgrade manually, download the updated package from
the SOT Linux FTP site (use the links above) or from one of our mirrors.
The list of mirrors can be obtained at www.sot.com/en/linux
Update the package with the following command:
rpm -Uvh
4. Verification
All packages are PGP signed by SOT for security.
You can verify each package with the following command:
rpm --checksig
If you wish to verify the integrity of the downloaded package, run
"md5sum " and compare the output with data given below.
Package Name MD5 sum
---------------------------------------------------------------------
/Desktop/i386/zlib-1.1.4-2.i386.rpm 480de5980733fca9d506afd278ed39d1
/Desktop/SRPMS/zlib-1.1.4-2.src.rpm dbd28eeb5c1e1ed2f6dbaef9254c8c6c
/Server/i386/zlib-1.1.4-2.i386.rpm 480de5980733fca9d506afd278ed39d1
/Server/SRPMS/zlib-1.1.4-2.src.rpm dbd28eeb5c1e1ed2f6dbaef9254c8c6c
Copyright(c) 2001-2003 SOT