Web Hosting Talk







View Full Version : Zlib Bug, it is a big problem?!?!


MasterBrian
03-14-2002, 05:19 AM
Hello,
I've read today morning of the bug of ZLIB. It seems that this library is used in the most of programs and O.S. around, like linux (all distr.) Microsoft WIndows, BSD and Solaris. The bug leave the system vulnerable to a particular DoS attack, and substitute the library with a new one it is not enought, in most of case, when the library is statically linked the program must be recompiled. In the case of linux also the Kernel is affected by this problem. Some distr. like Mandrake, Redhat and Debian are working to a new version that have the new lib, no ufficial news from microsoft of course and I don't know nothing about other O.S.
What do you think about?
ByeZ

zupanm
03-14-2002, 10:26 AM
here is a very partial list of apps that are effected

http://www.gzip.org/zlib/apps.html

This just isn't a dos problem. It can be a rootable problem if a program using zlib was a suid bit.

here is a very basic scanner

http://cert.uni-stuttgart.de/files/fw/find-zlib