Wide-ranging flaw crashes programs

By Joris Evers, CNET News.com
Friday, July 08, 2005 10:39 AM

A security flaw in a widely-used data compression technology could put many software programs at risk of attack, experts have warned.

The buffer overflow vulnerability exists in the open-source "zlib" component, Secunia said in an alert published Thursday. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib, the security monitoring company said.

The process is used in a large number of open-source and proprietary software applications to compress and decompress data, and it ships with many Linux and BSD distributions. Zlib is described as "something of a de facto standard" by Wikipedia, the community-based online encyclopedia.

"Just about everything uses zlib, from Xbox games consoles and mobile phones to OpenSSH, so the potential impact is very high," Tavis Ormandy of the Gentoo Linux security audit team wrote in an e-mail interview. Ormandy is credited with discovering the vulnerability.

The flaw has been reported in version 1.2.2 of zlib, Secunia said, and earlier versions may also be affected.

Secunia rates the problem "highly critical," one notch below its highest risk rating, because there is no known exploit. The French Security Incident Response Team deems it "critical," its most serious rating.

Assessing the impact
The security vulnerability may affect many applications, but the potential impact is not simple to calculate, said Michael Sutton, a lab director at security company iDefense. "The exploitability may also depend on how the library was implemented, so we can't assume that all applications using zlib are immediately vulnerable," he said.

It won't be an easy task to exploit the vulnerability to run code on a victim's device or computer, Ormandy said. However, it is not hard to make applications crash, he noted. "We have some test cases that trigger the bug via images or browsers that use zlib," Ormandy said.

An update to zlib, version 1.2.3, is being prepared and tested for release to eliminate this vulnerability, Mark Adler, co-creator of the compression library, said in an e-mail to CNET News.com.

Fixes are already available for several Linux releases, including Suse, Red Hat, Gentoo, Ubuntu, Mandriva and Debian, according to the Secunia Web site. An update is also available for FreeBSD, it said.

Microsoft is still looking into the issue, a company representative said. "Initial investigation has revealed that currently supported versions of Microsoft Windows are not at risk from this vulnerability," the representative said. Microsoft has used zlib in programs such as Office, MSN Messenger and Internet Explorer, according to a list of applications that use the component posted by the zlib developers group on its Web site.

This is not the first flaw in zlib. Last year, a denial of service vulnerability was reported in the compression component, and three years ago, a problem in zlib memory-management functions raised concerns for remote attacks.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Replicating your infrastructure in a lab

Enterprise Servers & Storage

Learn two ways to replicate your current environment for testing and evaluation of new server platforms.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? HPC is not just reserved for the some obscure high-end scientific studies.

    David Scott from Intel Corporation gives you a quick tour to the process of developing HPC applications and the interesting world of HPC Applications in today's industries, including the lucrative oil industry.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajendhiran Sanggaran from Oracle explains the processes and important considerations required to enable IT to fuel your business to the next level of growth.
    Play video

Tags

  1. antivirus
  2. asian
  3. attacks
  4. banking
  5. banks
  6. by
  7. cards
  8. china
  9. exploit
  10. firefox
  11. google
  12. holes
  13. mac
  14. malware
  15. microsoft
  16. mobile
  17. online
  18. os
  19. prompts
  20. security
  21. site
  22. threat
  23. trojan
  24. uk
  25. victims
  26. vista
  27. warning
  28. warns
  29. windows
  30. xp

What's the Indian definition of privacy?

Blog thumbnail

Two days back, I was having dinner at an aunt’s place. She is a leading doctor. She and I were discussing my school friend, who happens to be her patient...... by Swati Prasad

Read more »