CVE-2005-2096

NameCVE-2005-2096
Descriptionzlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1026-1, DSA-740-1, DSA-797-1, DSA-797-2
NVD severityhigh (attack range: remote)
Debian Bugs309196, 317133, 317523, 317966, 317967, 317968, 317970, 317971, 318014, 318069, 318091, 318097, 318099, 318100, 318246, 319858, 332236

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
aide (PTS)wheezy0.15.1-8fixed
jessie0.16~a2.git20130520-3fixed
stretch, sid0.16~b1-1fixed
bacula (PTS)wheezy5.2.6+dfsg-9fixed
jessie5.2.6+dfsg-9.3fixed
stretch, sid7.0.5+dfsg-4fixed
dar (PTS)wheezy2.4.5.debian.1-1fixed
jessie2.4.15-1fixed
stretch2.5.3-1fixed
sid2.5.4-1fixed
dpkg (PTS)wheezy (security), wheezy1.16.17fixed
jessie (security), jessie1.17.26fixed
stretch, sid1.18.4fixed
dump (PTS)wheezy0.4b44-1fixed
jessie0.4b44-5fixed
stretch, sid0.4b44-8fixed
ia32-libs (PTS)wheezy1:0.4fixed
libphysfs (PTS)wheezy2.0.2-6fixed
jessie2.0.3-2fixed
stretch, sid2.0.3-3fixed
mrtg (PTS)jessie, wheezy2.17.4-2fixed
stretch, sid2.17.4-4fixed
pvpgn (PTS)wheezy/contrib1.8.1-2.1fixed
stretch/contrib, jessie/contrib, sid/contrib1.8.5-2fixed
rpm (PTS)wheezy (security), wheezy4.10.0-5+deb7u2fixed
jessie4.11.3-1.1fixed
stretch, sid4.12.0.1+dfsg1-3fixed
rsync (PTS)wheezy3.0.9-4fixed
jessie, stretch, sid3.1.1-3fixed
sash (PTS)wheezy3.7-12fixed
jessie, stretch, sid3.8-3fixed
texmacs (PTS)wheezy1:1.0.7.15-2fixed
zlib (PTS)wheezy1:1.2.7.dfsg-13fixed
jessie, stretch, sid1:1.2.8.dfsg-2fixed
zsync (PTS)jessie, stretch, wheezy, sid0.6.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aidesource(unstable)0.10-6.1.1unimportant317523
aidesourcewoody(not affected)
amd64-libssource(unstable)1.3medium317970
amd64-libssourcewoody(not affected)
baculasource(unstable)1.36.3-2medium318014
baculasourcewoody(not affected)
darsource(unstable)(not affected)
dpkgsource(unstable)1.13.11unimportant317967
dpkgsourcewoody(not affected)
dumpsource(unstable)0.4b40-1low317966
dumpsourcewoody(not affected)
ia32-libssource(unstable)1.6medium317971
ia32-libssourcewoody(not affected)
libphysfssource(unstable)1.0.0-5unimportant318091
libphysfssourcewoody(not affected)
mrtgsource(unstable)(not affected)
mysql-dfsg-4.1source(unstable)4.1.13-1unimportant319858
oopssource(unstable)1.5.23.cvs-3medium318097
pvpgnsource(unstable)1.7.8-2high332236
rageircdsource(unstable)2.0.0-3sid1medium309196
rpmsource(unstable)4.0.4-31.1unimportant318099
rpmsourcewoody(not affected)
rsyncsource(unstable)(not affected)
sashsource(unstable)3.7-6medium318069, 318246
sashsourcesarge3.7-5sarge1highDSA-1026-1
sashsourcewoody(not affected)
systemimager-sshsource(unstable)(not affected)
texmacssource(unstable)1:1.0.5-3medium318100
texmacssourcewoody(not affected)
zlibsource(unstable)1:1.2.2-7medium317133
zlibsourcesarge1:1.2.2-4.sarge.1mediumDSA-740-1
zlibsourcewoody(not affected)DSA-740-1
zsyncsource(unstable)0.4.0-2medium317968
zsyncsourcesarge0.3.3-1.sarge.1mediumDSA-797-1

Notes

Several packages ship embedded copies of zlib, there are a lot probably more
Florian Weimer is doing a comprehensive audit using clamav
to search for static zlib signatures in binaries in Debian
Not all of the listed packages have been checked for actual
exploitability using this hole.
oldstable (woody) had zlib 1.1, which is not affected
[woody] - dpkg <not-affected> (Woody contains zlib 1.1, which is not affected)
You need to trust debs anyway, when installing them
[woody] - dump <not-affected> (Woody contains zlib 1.1, which is not affected)
[sarge] - dump <no-dsa> (Backups do not contain untrusted data)
[woody] - aide <not-affected> (Woody contains zlib 1.1, which is not affected)
aide only uses zlib to compress/decompress internal data
[woody] - amd64-libs <not-affected> (Woody contains zlib 1.1, which is not affected)
[woody] - ia32-libs <not-affected> (Woody contains zlib 1.1, which is not affected)
- dar <not-affected> (zlib not used on unstrusted input, see #317989)
[woody] - bacula <not-affected> (Woody contains zlib 1.1, which is not affected)
[sarge] - bacula <no-dsa> (Backups do not contain untrusted data)
[woody] - sash <not-affected> (Woody contains zlib 1.1, which is not affected)
[woody] - libphysfs <not-affected> (Woody contains zlib 1.1, which is not affected)
[woody] - rpm <not-affected> (Woody contains zlib 1.1, which is not affected)
You need to trust rpms anyway, when installing them
- systemimager-ssh <not-affected> (bug #318101; unimportant)
see dannf's first bug comment; systemimager-ssh doesn't use compression
[woody] - texmacs <not-affected> (Woody contains zlib 1.1, which is not affected)
[sarge] - texmacs <no-dsa> (Hardly exploitable)
- mrtg <not-affected> (Only used for internal compression, current versions link dynamically)
- rsync <not-affected> (Uses zlib 1.1, which is not affected)
rsync upstream updated the internal zlib copy in 2.6.6 without real need,
as the included version was never affected, despite claiming them so.

Search for package or bug name: Reporting problems