zlib Update for Mandrake
Posted on: 03/19/2003 02:20 PM

MandrakeSoft has released zlib update for Mandrake Linux 7.2 - 9.0

Richard Kettlewell discovered a buffer overflow vulnerability in the zlib library's gzprintf() function. This can be used by attackers to cause a denial of service or possibly even the execution of arbitrary code. Our thanks to the OpenPKG team for providing a patch which adds the necessary configure script checks to always use the secure vsnprintf(3) and snprintf(3) functions, and which additionally adjusts the code to correctly take into account the return value of vsnprintf(3) and snprintf(3).


Read more


Printed from Linux Compatible (http://www.linuxcompatible.org/news/story/zlib_update_for_mandrake.html)