Issued:
2005-07-21
Updated:
2005-07-21

RHSA-2005:584 - zlib security update


Synopsis

zlib security update

Type/Severity

Security Advisory Important

Topic

Updated zlib packages that fix a buffer overflow are now available for Red Hat Enterprise Linux 4.

This update has been rated as having important security impact by the Red Hat Security Response Team.

Description

Zlib is a general-purpose lossless data compression library that is used by many different programs.

A previous zlib update, RHSA-2005:569 (CAN-2005-2096) fixed a flaw in zlib that could allow a carefully crafted compressed stream to crash an application. While the original patch corrected the reported overflow, Markus Oberhumer discovered additional ways a stream could trigger an overflow. An attacker could create a carefully crafted compressed stream that would cause an application to crash if the stream is opened by a user. As an example, an attacker could create a malicious PNG image file that would cause a Web browser or mail viewer to crash if the image is viewed. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CAN-2005-1849 to this issue.

Note that the versions of zlib shipped with Red Hat Enterprise Linux 2.1 and 3 are not vulnerable to this issue.

All users should update to these errata packages that contain a patch from Mark Adler that corrects this issue.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

Affected Products

ProductVersionArch
Red Hat Enterprise Linux for Power, big endian4ppc
Red Hat Enterprise Linux for IBM z Systems4s390x
Red Hat Enterprise Linux for IBM z Systems4s390
Red Hat Enterprise Linux Workstation4x86_64
Red Hat Enterprise Linux Workstation4ia64
Red Hat Enterprise Linux Workstation4i386
Red Hat Enterprise Linux Server4x86_64
Red Hat Enterprise Linux Server4ia64
Red Hat Enterprise Linux Server4i386
Red Hat Enterprise Linux Desktop4x86_64
Red Hat Enterprise Linux Desktop4i386

Updated Packages

  • zlib-1.2.1.2-1.2.i386.rpm
  • zlib-1.2.1.2-1.2.ppc.rpm
  • zlib-devel-1.2.1.2-1.2.x86_64.rpm
  • zlib-1.2.1.2-1.2.s390x.rpm
  • zlib-1.2.1.2-1.2.ppc64.rpm
  • zlib-devel-1.2.1.2-1.2.ppc.rpm
  • zlib-devel-1.2.1.2-1.2.i386.rpm
  • zlib-1.2.1.2-1.2.x86_64.rpm
  • zlib-devel-1.2.1.2-1.2.s390.rpm
  • zlib-1.2.1.2-1.2.src.rpm
  • zlib-1.2.1.2-1.2.ia64.rpm
  • zlib-devel-1.2.1.2-1.2.ia64.rpm
  • zlib-1.2.1.2-1.2.s390.rpm
  • zlib-devel-1.2.1.2-1.2.ppc64.rpm
  • zlib-devel-1.2.1.2-1.2.s390x.rpm

Fixes

CVEs

References

(none)


Additional information