★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/security_sources_article-4582.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Security Sources 3/14/2002 16:46

Significant Vulnerability Afflicts Linux Systems

By LinuxSecurity
Posted By: Dave Wreski
3/14/2002

Today in a coordinated effort between all major Linux vendors, a vulnerability in the zlib library was announced, potentially affecting every installed Linux system in existance.

The vulnerability is rooted in the free() function and how it used. Quoting from the EnGarde Secure Linux advisory, "The zlib shared library may attempt to free() a memory region more then once, potentially yielding a system exploitable by certain programs that use it for decompression. Because certain packages include their own zlib implementation or statically link against the system zlib, several packages need to be updated to properly fix this bug."

This vulnerability will also affect some vendors shipping implementations of the open source library within their binary applications.

Packages including X11, rsync, the Linux kernel, QT, mozilla, gcc, vnc, and many other programs that have the ability to use network compression are potentially vulnerable.

The reason this particular vulnerability is so significant is because many programs implement their own particular version of the zlib library, statically linked with their code, and therefore inheriting the potential for exploit.

No known exploit is available for this vulnerability at this time, but the implications of this vulnerability are significant, and have the potential for remote compromise leading to root privileges on the server.

As vendors post their advisories, LinuxSecurity will continue to update this page and our site, directing the Linux and open source security communities to the authoritative information from their Linux vendor.

Resources

Thanks to Ryan W. Maple for assistance with this report. This page will be updated continually, as vendors file their vulnerability reports.

Hardening Sendmail
Mar 15

Definitive guide to writing a Linux virus
Mar 15

Linux Advisory Watch - March 15th 2002
Mar 15

Significant Vulnerability Afflicts Linux Systems
Mar 14

Privacy software makes post 9-11 comeback
Mar 14

D.I.R.T. Spyware Exposed on Web
Mar 14

Cable Modem Hacking Tricks Uncapped Online
Mar 14

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000