OSVDB ID: 9361

Title: zlib inflateBack Function Error Handling DoS

Info

Disclosure

Aug 30, 2004

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Zlib contains a flaw that may allow a local denial of service. The issue is triggered when the inflateBack() function processes a specifically crafted file, and will result in loss of availability for the service.

Classification

Location: Local Access Required
Attack Type: Denial of Service
Impact: Loss of Availability
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, various Linux distributions have released patches to address this vulnerability.

Products

zlib

zlib

1.2.1

References

Credit

  • Johan Thelmén -


Direct URL: http://osvdb.org/9361