[ Thanks to SOT Linux
Security Team for this link. ]
--------------------------------------------------------------------- SOT Linux Security Advisory Subject: Updated zlib package for SOT Linux 2002 Advisory ID: SLSA-2003:21 Date: Monday, May 5, 2003 Product: SOT Linux 2002 --------------------------------------------------------------------- 1. Problem description Zlib is a general-purpose, patent-free, lossless data compression library used by many different programs. The function gzprintf within zlib, when called with a string longer than Z_PRINTF_BUFZISE (= 4096 bytes), can overflow without giving a warning. zlib-1.1.4 and earlier exhibit this behavior. There are no known exploits of the gzprintf overrun, and only a few programs, including rpm2html and gimp-print, are known to use the gzprintf function. The problem has been fixed by checking the length of the output string within gzprintf. 2. Updated packages SOT Linux 2002 Desktop: i386: ftp://ftp.sot.com/updates/2002/Desktop/i386/zlib-1.1.4-2.i386.rpm SRPMS: ftp://ftp.sot.com/updates/2002/Desktop/SRPMS/zlib-1.1.4-2.src.rpm SOT Linux 2002 Server: i386: ftp://ftp.sot.com/updates/2002/Server/i386/zlib-1.1.4-2.i386.rpm SRPMS: ftp://ftp.sot.com/updates/2002/Server/SRPMS/zlib-1.1.4-2.src.rpm 3. Upgrading package Before applying this update, make sure all previously released errata relevant to your system have been applied. Use up2date to automatically upgrade the fixed packages. If you want to upgrade manually, download the updated package from the SOT Linux FTP site (use the links above) or from one of our mirrors. The list of mirrors can be obtained at www.sot.com/en/linux Update the package with the following command: rpm -Uvh 4. Verification All packages are PGP signed by SOT for security. You can verify each package with the following command: rpm --checksig If you wish to verify the integrity of the downloaded package, run "md5sum " and compare the output with data given below. Package Name MD5 sum --------------------------------------------------------------------- /Desktop/i386/zlib-1.1.4-2.i386.rpm 480de5980733fca9d506afd278ed39d1 /Desktop/SRPMS/zlib-1.1.4-2.src.rpm dbd28eeb5c1e1ed2f6dbaef9254c8c6c /Server/i386/zlib-1.1.4-2.i386.rpm 480de5980733fca9d506afd278ed39d1 /Server/SRPMS/zlib-1.1.4-2.src.rpm dbd28eeb5c1e1ed2f6dbaef9254c8c6c Copyright(c) 2001-2003 SOT