On TechRepublic: Linux desktops have tanked: Get over it
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 7, 2005 11:16:00 PM

A security flaw in a widely-used data compression technology could put many software programs at risk of attack, experts have warned.

The buffer overflow vulnerability exists in the open-source "zlib" component, Secunia said in an alert published Thursday. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib, the security monitoring company said.

The process is used in a large number of open-source and proprietary software applications to compress and decompress data, and it ships with many Linux and BSD distributions. Zlib is described as "something of a de facto standard" by Wikipedia, the community-based online encyclopedia.

"Just about everything uses zlib, from Xbox games consoles and mobile phones to OpenSSH, so the potential impact is very high," Tavis Ormandy of the Gentoo Linux security audit team wrote in an e-mail interview. Ormandy is credited with discovering the vulnerability.

The flaw has been reported in version 1.2.2 of zlib, Secunia said, and earlier versions may also be affected.

Secunia rates the problem "highly critical," one notch below its highest risk rating, because there is no known exploit. The French Security Incident Response Team deems it "critical," its most serious rating.

Assessing the impact
The security vulnerability may affect many applications, but the potential impact is not simple to calculate, said Michael Sutton, a lab director at security company iDefense. "The exploitability may also depend on how the library was implemented, so we can't assume that all applications using zlib are immediately vulnerable," he said.

It won't be an easy task to exploit the vulnerability to run code on a victim's device or computer, Ormandy said. However, it is not hard to make applications crash, he noted. "We have some test cases that trigger the bug via images or browsers that use zlib," Ormandy said.

An update to zlib, version 1.2.3, is being prepared and tested for release to eliminate this vulnerability, Mark Adler, co-creator of the compression library, said in an e-mail to CNET News.com.

Fixes are already available for several Linux releases, including Suse, Red Hat, Gentoo, Ubuntu, Mandriva and Debian, according to the Secunia Web site. An update is also available for FreeBSD, it said.

Microsoft is still looking into the issue, a company representative said. "Initial investigation has revealed that currently supported versions of Microsoft Windows are not at risk from this vulnerability," the representative said. Microsoft has used zlib in programs such as Office, MSN Messenger and Internet Explorer, according to a list of applications that use the component posted by the zlib developers group on its Web site.

This is not the first flaw in zlib. Last year, a denial of service vulnerability was reported in the compression component, and three years ago, a problem in zlib memory-management functions raised concerns for remote attacks.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 57 Talkback(s)
It's about time Capt'n Hook
And wash the parrot sh*t off your back.
Gaaarrrr!

wink... (Read the rest)
Posted by: osreinstall Posted on: 07/12/05 You are currently: a Guest | | Terms of Use
Uh Oh ----  I_am_hellion_z | 07/07/05
Wide-ranging flaw crashes programs  Loverock Davidson | 07/07/05
apparently you missed the part  Monkey_MCSE | 07/07/05
Yep. BSD is affected too.  toadlife | 07/08/05
Yup  Michael Kelly | 07/08/05
I'm compiling it now...  toadlife | 07/08/05
No  Richard Flude | 07/07/05
Re: Wide-ranging flaw crashes programs  joe6pack_z | 07/07/05
What did you expect when...  thetargos | 07/08/05
The amount of abuse Linux can take...  Sabz5150 | 07/07/05
Note: By not related to Linux/OSS, I am referring to Acrobat  Sabz5150 | 07/07/05
Ohh, poor lovey..  widge_z | 07/08/05
OK. The 3rd bug in zlib but the  michael_t | 07/07/05
Headline design  vferrara | 07/07/05
It threw me off initially since all the sensational  michael_t | 07/07/05
Americans in general don't mind outsourcing  Paco20 | 07/07/05
Ooops! Wrong Article  Paco20 | 07/07/05
At least with this zlib vulnerability the other "typical" news:  michael_t | 07/07/05
You can't help yourself, can you...  vferrara | 07/07/05
Pot, Kettle, Black...  Sabz5150 | 07/07/05
I dare you...  vferrara | 07/08/05
Howdy there  michael_t | 07/07/05
Overstatement  vferrara | 07/08/05
Neetd to be more technical, logical or funnier at least.  michael_t | 07/08/05
Gee Mr T  vferrara | 07/09/05
Poor Vincense... nothing works for you.  michael_t | 07/11/05
Yea Suuuuuure!  osreinstall | 07/09/05
Security as the goal  vferrara | 07/09/05
So precisely how seriously DO you take security?  Zogg | 07/11/05
Security is another attribute  osreinstall | 07/11/05
Linux gives you the keys you need, and no others.  Zogg | 07/11/05
Only an idiot would do online purchases  osreinstall | 07/11/05
You've just called all E-Bay and PayPal users "idiots"  Zogg | 07/12/05
They are idiots  osreinstall | 07/12/05
Sounds like you don't want a PC at all!  Zogg | 07/12/05
You are wrong Zog  osreinstall | 07/12/05
Even DRM-approved programs are buggy.  Zogg | 07/12/05
Here is the translation  osreinstall | 07/12/05
That's the spin, not the translation.  Zogg | 07/12/05
Your days are numbered  osreinstall | 07/12/05
Spin and BS. I'm done with you. (NT).  Zogg | 07/12/05
It's about time Capt'n Hook  osreinstall | 07/12/05
Nice that ZDNET publishes these vulns ...  George Mitchell | 07/07/05
Doesn't Cost a Dime as Long As ...  PMC-CON | 07/08/05
Would this affect my new iMac G5?  Paco20 | 07/07/05
I would say no.  toadlife | 07/08/05
Mac immune!  An_Axe_to_Grind | 07/08/05
no OS is immune. this is a problem with a graphical component that has  wessonjoe | 07/08/05
It is?  rpmyers1 | 07/08/05
Must Not Be True ... "Many Eyes ...  PMC-CON | 07/08/05
Have YOU done it too for your OS? (NT)  thetargos | 07/08/05
Apparently it works very well.  michael_t | 07/08/05
Many Eyes on zlib  Marc Thibault | 07/09/05
Another Buffer Overflow?  RimaDog@... | 07/08/05
Real issue.  Anton Philidor | 07/08/05
Doesn't MS also use zlib?  Zogg | 07/08/05
when we get the email...  linuxoverwindows | 07/08/05

What do you think?

SmartPlanet

Click Here