---

SOT Linux Advisory: zlib

[ Thanks to SOT Linux
Security Team
for this link. ]


---------------------------------------------------------------------
                   SOT Linux Security Advisory

Subject:           Updated zlib package for SOT Linux 2002
Advisory ID:       SLSA-2003:21
Date:              Monday, May 5, 2003
Product:           SOT Linux 2002
---------------------------------------------------------------------

1. Problem description

Zlib is a general-purpose, patent-free, lossless data compression
library used by many different programs.

The function gzprintf within zlib, when called with a string longer than
Z_PRINTF_BUFZISE (= 4096 bytes), can overflow without giving a warning.

zlib-1.1.4 and earlier exhibit this behavior. There are no known exploits
of the gzprintf overrun, and only a few programs, including rpm2html
and gimp-print, are known to use the gzprintf function.

The problem has been fixed by checking the length of the output string
within gzprintf.




2. Updated packages

SOT Linux 2002 Desktop:
 
i386:
ftp://ftp.sot.com/updates/2002/Desktop/i386/zlib-1.1.4-2.i386.rpm
 
SRPMS:
ftp://ftp.sot.com/updates/2002/Desktop/SRPMS/zlib-1.1.4-2.src.rpm
 
 
SOT Linux 2002 Server:
 
i386:
ftp://ftp.sot.com/updates/2002/Server/i386/zlib-1.1.4-2.i386.rpm

SRPMS:
ftp://ftp.sot.com/updates/2002/Server/SRPMS/zlib-1.1.4-2.src.rpm


3. Upgrading package

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Use up2date to automatically upgrade the fixed packages.
 
If you want to upgrade manually, download the updated package from
the SOT Linux FTP site (use the links above) or from one of our mirrors.
The list of mirrors can be obtained at www.sot.com/en/linux
 
Update the package with the following command:
rpm -Uvh 


4. Verification

All packages are PGP signed by SOT for security.
 
You can verify each package with the following command:
rpm --checksig  
 
If you wish to verify the integrity of the downloaded package, run
"md5sum " and compare the output with data given below.
 
 
Package Name                             MD5 sum
---------------------------------------------------------------------
/Desktop/i386/zlib-1.1.4-2.i386.rpm      480de5980733fca9d506afd278ed39d1
/Desktop/SRPMS/zlib-1.1.4-2.src.rpm      dbd28eeb5c1e1ed2f6dbaef9254c8c6c
/Server/i386/zlib-1.1.4-2.i386.rpm       480de5980733fca9d506afd278ed39d1
/Server/SRPMS/zlib-1.1.4-2.src.rpm       dbd28eeb5c1e1ed2f6dbaef9254c8c6c


Copyright(c) 2001-2003 SOT

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends, & analysis