search menu icon-carat-right cmu-wordmark

CERT Coordination Center

zlib "gzprintf()" function vulnerable to buffer overflow

Vulnerability Note VU#142121

Original Release Date: 2003-05-23 | Last Revised: 2008-06-06

Overview

A buffer overflow exists in one of the functions included with the zlib compression library. This vulnerability may allow a remote attacker to execute arbitrary code or cause a denial of service. An exploit for this vulnerability is publicly available.

Description

The zlib website describes zlib as a "...lossless data-compression library for use on virtually any computer hardware and operating system." A buffer overflow exists in the gzprintf function contained within the zlib compression library. For more detailed information, please see Richard Kettlewell's advisory.

Impact

A remote attacker may be able to execute code or cause a denial of service.

Solution

Apply a vendor patch.

Vendor Information

142121
 

View all 62 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was discovered by Richard Kettlewell.

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2003-0107
Severity Metric: 29.11
Date Public: 2003-02-22
Date First Published: 2003-05-23
Date Last Updated: 2008-06-06 17:03 UTC
Document Revision: 11

Sponsored by CISA.