Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:9641
HistorySep 03, 2005 - 12:00 a.m.

zsync Multiple zlib Vulnerabilities

2005-09-0300:00:00
vulners.com
17

zsync Multiple zlib Vulnerabilities

Secunia Advisory: SA16672
Release Date: 2005-09-02

Critical:
Moderately critical
Impact: DoS
System access

Where: From remote

Solution Status: Unpatched

Software: zsync 0.x

Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

CVE reference: CAN-2005-1849
CAN-2005-2096

Description:
Some vulnerabilities have been reported in zsync, which can be exploited by malicious people to conduct a DoS (Denial of Service) or potentially compromise a user's system.

The vulnerabilities are caused due to the use of a vulnerable version of zlib.

For more information:
SA15949
SA16137

Solution:
Restrict use of zsync to connect to trusted servers only.

Some vendors have released fixed packages.

Original Advisory:
Debian:
http://www.debian.org/security/2005/dsa-797

Other References:
SA15949:
http://secunia.com/advisories/15949/

SA16137:
http://secunia.com/advisories/16137/

Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.