Jump to content

Advisories MDVSA-2009:157: perl-Compress-Raw-Zlib


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in perl-Compress-Raw-Zlib:

 

Off-by-one error in the inflate function in Zlib.xs in

Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS,

SpamAssassin, and possibly other products, allows context-dependent

attackers to cause a denial of service (hang or crash) via a crafted

zlib compressed stream that triggers a heap-based buffer overflow,

as exploited in the wild by Trojan.Downloader-71014 in June 2009

(CVE-2009-1391).

 

This update provides fixes for this vulnerability.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...