CVE Vulnerabilities

CVE-2005-2096

Published: Jul 06, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.

Affected Software

NameVendorStart VersionEnd Version
ZlibZlib1.2.0 (including)1.2.0 (including)
ZlibZlib1.2.1 (including)1.2.1 (including)
ZlibZlib1.2.2 (including)1.2.2 (including)
Red Hat Enterprise Linux 4RedHatzlib-0:1.2.1.2-1.1*
Red Hat Network Satellite Server v 4.2RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.0RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 5.0RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.1RedHatrhn-solaris-bootstrap-0:5.1.1-3*
Red Hat Network Satellite Server v 5.1RedHatrhn_solaris_bootstrap_5_1_1_3-0:1-0*
AideUbuntudapper*
AideUbuntudevel*
AideUbuntuedgy*
AideUbuntufeisty*
BaculaUbuntudapper*
BaculaUbuntuedgy*
BaculaUbuntufeisty*
DumpUbuntudapper*
DumpUbuntudevel*
DumpUbuntuedgy*
DumpUbuntufeisty*
Ia32-libsUbuntudapper*
Ia32-libsUbuntudevel*
Ia32-libsUbuntuedgy*
Ia32-libsUbuntufeisty*
RpmUbuntudapper*
RpmUbuntudevel*
RpmUbuntuedgy*
RpmUbuntufeisty*
ZlibUbuntudapper*
ZlibUbuntudevel*
ZlibUbuntuedgy*
ZlibUbuntufeisty*
ZsyncUbuntudapper*
ZsyncUbuntudevel*
ZsyncUbuntuedgy*
ZsyncUbuntufeisty*

References