[Zlib-announce] zlib 1.2.1 and 1.2.2 security vulnerability (fwd)

Bob Friesenhahn <[email protected]> Sun, 10 Jul 2005 16:18:17 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.announce
Message-ID <[email protected]>
This vulnerability likely effects GraphicsMagick or any other 
application which depends on zlib.

Bob
---------- Forwarded message ----------
Date: Sun, 10 Jul 2005 14:12:15 -0700
From: Mark Adler <[email protected]>
To: [email protected]
Subject: [Zlib-announce] zlib 1.2.1 and 1.2.2 security vulnerability

zlib-announce list members,

A security vulnerability has been discovered in which specially crafted input 
files can cause inflate to overwrite memory that follows the internal inflate 
state.  This can cause the application to crash depending on what is 
overwritten.  This vulnerability only affects versions 1.2.1 and 1.2.2. of 
zlib.  Earlier versions, e.g. 1.1.4, are not affected.

A new version of zlib will be released soon to address this issue.  Stay tuned.

Mark Adler


_______________________________________________
Zlib-announce mailing list
[email protected]
http://madler.net/mailman/listinfo/zlib-announce_madler.net


-------------------------------------------------------
This SF.Net email is sponsored by the 'Do More With Dual!' webinar happening
July 14 at 8am PDT/11am EDT. We invite you to explore the latest in dual
core and dual graphics technology at this free one hour event hosted by HP, 
AMD, and NVIDIA.  To register visit http://www.hp.com/go/dualwebinar