CVE-2005-2096Improper Restriction of Operations within the Bounds of a Memory Buffer in Zlib

12 documents9 sources
Severity
7.5HIGHNVD
EPSS
43.0%
top 2.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 6
Latest updateMay 3

Description

zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages21 packages

debiandebian/zlib< aide 0.10-6.1.1 (bookworm)
Debianzlib/zlib< 1:1.2.2-7+3
NVDzlib/zlib1.2.0, 1.2.1, 1.2.2+2
debiandebian/dar< aide 0.10-6.1.1 (bookworm)
debiandebian/rpm< aide 0.10-6.1.1 (bookworm)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w2qv-rhm9-97p2: zlib 12022-05-03
OSV
CVE-2005-2096: zlib 12005-07-06
CVEList
CVE-2005-2096: zlib 12005-07-06

📋Vendor Advisories

6
Ubuntu
rpm vulnerability2005-11-09
Ubuntu
zlib vulnerabilities2005-10-29
Ubuntu
zlib vulnerabilities2005-07-23
Red Hat
zlib DoS2005-07-06
Ubuntu
zlib vulnerability2005-07-06

💬Community

1
Bugzilla
CVE-2005-2096 zlib DoS2008-01-29