Language Selection

English French German Italian Portuguese Spanish

Zlib Security Flaw Exposes Swath of Programs

Filed under
Security

A serious security flaw has been identified in Zlib, a widely used data compression library. Fixes have begun to appear, but a large number of programs could be affected.

Zlib is a data compression library that is used by many third-party programs and is distributed with many operating systems, including many Linux and BSD distributions.

Microsoft Corp. and other proprietary software companies also use the library in many programs. These companies can do so because Zlib is licensed under liberal BSD-style license.

This isn't the first time that the popular Zlib has been the center of a security concern. In 2002, a problem with how it handled memory allocation became a major concern.

This time, the flaw is a buffer overflow in the decompression process. Because the program doesn't properly validate input data, it can be fed bad data, which can lead to a buffer overflow.

This, in turn, means that if a user opens a file with a Zlib-enabled application, such as a Web browser or data compression tool, which contains specially malformed compressed data, an attacker could execute arbitrary code as the user. If this user were running as a system administrator the flaw would run at that level as well.

Since Zlib is so ubiquitous, this represents a serious security concern.

It's not clear how many programs are affected, but some operating system distributions are widely exposed. According to one source, numerous key packages in the Fedora Core 3 distribution use Zlib. Symantec Corp. reports that AIX, Debian, FreeBSD, Gentoo, SuSE, Red Hat, Ubuntu and many other operating systems are affected.

Full Story.

UPDATE: Linux vendors pump out highly critical patch.

More in Tux Machines

Linux: Come for the Kernel, Stay for the Popcorn

Linux offers so much for users to sink their teeth into that even among desktop and more casual users, it's easy to get caught up in the tradecraft. It's only too tempting to put your system's technical capabilities to the test by trying out a new program or practicing a new command. As with any other interest, though, Linux is not much fun unless you can revel in it with fellow fans and enjoy the camaraderie. Here's a short tour of some of the major cultural hallmarks of the vibrant Linux world, and some of the hubs where you can witness and indulge in the Linux life. Read more

DeVeDe NG Review Create Video DVDs and CDs

​Devede is an open source program that allows the creation of video CDs and DVDs from an MPEG, AVI and similar formats suitable for home DVD players. Devede uses Mplayer, Mencoder, DVDAuthor, and VCDimager, so you can use any video playable with Mplayer. It is available for multiple platforms including Windows and Linux. Read
more

Android Leftovers

Pixelbook leak: Google's new high-end Chromebook expected October 4

According to Droid Life, on October 4, Google will release the first new retail version of the Chromebook Pixel since 2015, the Pixelbook. The Chomebook Pixel was the Rolls-Royce of Chromebooks. It was faster, more powerful, and came with a better display than any other laptop in its day. Google, however, decided that, while the company would still release new Pixels for in-house use, it wouldn't sell them. Thanks to Chromebook Pixel fans, Google has elected to start selling this luxury Chromebook again. Read more