Zlib security heads up

John Hinsley johnhinsley at blueyonder.co.uk
Fri Mar 15 23:25:52 UTC 2002


Zlib is the OpenSource compression library used in (at least) Linux, BDS and
Windows.

A bug has been discovered which potentially leaves a system open to root
exploits.

Patches are available for all major Linux distros and, AFAIK, BSD. You should
go to your distro's site and download and apply the patch ASAP. Alan Cox has
flagged this as "urgent".

As this library is covered by a BSD like licence (so that changed code does
not have to be "returned" to the community) it's unclear as to whether Windows'
code still contains the bug, although people running black-box tests on
Windows report that it displays symptoms which suggest it does. Zlib is used
in at least 7 major Microsoft applications.

There's some more detail on:

http://news.com.com/2100-1001-860328.html

Cheers

John
-- 
They're afraid, very afraid......
According to CRN magazine, Microsoft staff discovering Linux in use
will have now access to a special 'escalation' team.
Now, where did I put that stake and mallet?
http://www.newsforge.com/article.pl?sid=02/01/16/0310222&mode=nocomment




More information about the Squeak-dev mailing list