• # from slack world

    Posté par . En réponse à la dépêche Buffer overflow via zlib. Évalué à 10.

    Extrait du change log de la slack 8 :
    Mon Mar 11 13:32:40 PST 2002
    patches/packages/zlib.tgz: Upgraded to zlib-1.1.4. This fixes a security
    problem which may introduce vulnerabilities into any program that links with
    zlib. Quoting the advisory on zlib.org:

    "Depending upon how and where the zlib routines are called from the given
    program, the resulting vulnerability may have one or more of the following
    impacts: denial of service, information leakage, or execution of arbitrary
    code."

    Sites are urged to upgrade the zlib package immediately.

    The complete advisory may be found here:
    http://www.zlib.org/advisory-2002年03月11日.txt(...)


    Le package de la zlib à jour est ici :
    ftp://ftp.lip6.fr/pub/linux/distributions/slackware/patches/packag(...)