CVE-2005-2096

NameCVE-2005-2096
Descriptionzlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1026-1, DSA-740-1, DSA-797-1, DSA-797-2
NVD severityhigh (attack range: remote)
Debian Bugs309196, 317133, 317523, 317966, 317967, 317968, 317970, 317971, 318014, 318069, 318091, 318097, 318099, 318100, 318246, 319858, 332236

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
aide (PTS)jessie0.16~a2.git20130520-3fixed
stretch0.16-1fixed
buster, sid0.16-3fixed
bacula (PTS)jessie5.2.6+dfsg-9.3fixed
stretch7.4.4+dfsg-6fixed
buster, sid9.0.8-1fixed
dar (PTS)jessie2.4.15-1fixed
stretch2.5.8-3fixed
buster2.5.15-1fixed
sid2.5.16-1fixed
dpkg (PTS)jessie1.17.27fixed
jessie (security)1.17.26fixed
stretch1.18.25fixed
buster, sid1.19.0.5fixed
dump (PTS)jessie0.4b44-5fixed
stretch0.4b46-3fixed
buster, sid0.4b46-5fixed
libphysfs (PTS)jessie2.0.3-2fixed
stretch2.0.3-5fixed
buster, sid3.0.1-2fixed
mrtg (PTS)jessie2.17.4-2fixed
stretch2.17.4-4fixed
buster, sid2.17.4-4.1fixed
pvpgn (PTS)jessie/contrib1.8.5-2fixed
buster/contrib, sid/contrib, stretch/contrib1.8.5-2.1fixed
rpm (PTS)jessie4.11.3-1.1fixed
stretch4.12.0.2+dfsg1-2fixed
buster, sid4.14.1+dfsg1-3fixed
rsync (PTS)jessie (security), jessie3.1.1-3+deb8u1fixed
stretch (security), stretch3.1.2-1+deb9u1fixed
buster, sid3.1.2-2.1fixed
sash (PTS)jessie, stretch3.8-3fixed
buster, sid3.8-5fixed
zlib (PTS)jessie1:1.2.8.dfsg-2fixed
stretch1:1.2.8.dfsg-5fixed
buster, sid1:1.2.11.dfsg-1fixed
zsync (PTS)jessie0.6.2-1fixed
stretch0.6.2-2fixed
buster, sid0.6.2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aidesource(unstable)0.10-6.1.1unimportant317523
aidesourcewoody(not affected)
amd64-libssource(unstable)1.3medium317970
amd64-libssourcewoody(not affected)
baculasource(unstable)1.36.3-2medium318014
baculasourcewoody(not affected)
darsource(unstable)(not affected)
dpkgsource(unstable)1.13.11unimportant317967
dpkgsourcewoody(not affected)
dumpsource(unstable)0.4b40-1low317966
dumpsourcewoody(not affected)
ia32-libssource(unstable)1.6medium317971
ia32-libssourcewoody(not affected)
libphysfssource(unstable)1.0.0-5unimportant318091
libphysfssourcewoody(not affected)
mrtgsource(unstable)(not affected)
mysql-dfsg-4.1source(unstable)4.1.13-1unimportant319858
oopssource(unstable)1.5.23.cvs-3medium318097
pvpgnsource(unstable)1.7.8-2high332236
rageircdsource(unstable)2.0.0-3sid1medium309196
rpmsource(unstable)4.0.4-31.1unimportant318099
rpmsourcewoody(not affected)
rsyncsource(unstable)(not affected)
sashsource(unstable)3.7-6medium318069, 318246
sashsourcesarge3.7-5sarge1highDSA-1026-1
sashsourcewoody(not affected)
systemimager-sshsource(unstable)(not affected)
texmacssource(unstable)1:1.0.5-3medium318100
texmacssourcewoody(not affected)
zlibsource(unstable)1:1.2.2-7medium317133
zlibsourcesarge1:1.2.2-4.sarge.1mediumDSA-740-1
zlibsourcewoody(not affected)DSA-740-1
zsyncsource(unstable)0.4.0-2medium317968
zsyncsourcesarge0.3.3-1.sarge.1mediumDSA-797-1

Notes

Several packages ship embedded copies of zlib, there are a lot probably more
Florian Weimer is doing a comprehensive audit using clamav
to search for static zlib signatures in binaries in Debian
Not all of the listed packages have been checked for actual
exploitability using this hole.
oldstable (woody) had zlib 1.1, which is not affected
[woody] - dpkg <not-affected> (Woody contains zlib 1.1, which is not affected)
You need to trust debs anyway, when installing them
[woody] - dump <not-affected> (Woody contains zlib 1.1, which is not affected)
[sarge] - dump <no-dsa> (Backups do not contain untrusted data)
[woody] - aide <not-affected> (Woody contains zlib 1.1, which is not affected)
aide only uses zlib to compress/decompress internal data
[woody] - amd64-libs <not-affected> (Woody contains zlib 1.1, which is not affected)
[woody] - ia32-libs <not-affected> (Woody contains zlib 1.1, which is not affected)
- dar <not-affected> (zlib not used on unstrusted input, see #317989)
[woody] - bacula <not-affected> (Woody contains zlib 1.1, which is not affected)
[sarge] - bacula <no-dsa> (Backups do not contain untrusted data)
[woody] - sash <not-affected> (Woody contains zlib 1.1, which is not affected)
[woody] - libphysfs <not-affected> (Woody contains zlib 1.1, which is not affected)
[woody] - rpm <not-affected> (Woody contains zlib 1.1, which is not affected)
You need to trust rpms anyway, when installing them
- systemimager-ssh <not-affected> (bug #318101; unimportant)
see dannf's first bug comment; systemimager-ssh doesn't use compression
[woody] - texmacs <not-affected> (Woody contains zlib 1.1, which is not affected)
[sarge] - texmacs <no-dsa> (Hardly exploitable)
- mrtg <not-affected> (Only used for internal compression, current versions link dynamically)
- rsync <not-affected> (Uses zlib 1.1, which is not affected)
rsync upstream updated the internal zlib copy in 2.6.6 without real need,
as the included version was never affected, despite claiming them so.

Search for package or bug name: Reporting problems