Mandrake Linux Security Advisory : zlib (MDKSA-2003:033)

High Nessus Plugin ID 14017


The remote Mandrake Linux host is missing one or more security updates.


Richard Kettlewell discovered a buffer overflow vulnerability in the zlib library's gzprintf() function. This can be used by attackers to cause a denial of service or possibly even the execution of arbitrary code. Our thanks to the OpenPKG team for providing a patch which adds the necessary configure script checks to always use the secure vsnprintf(3) and snprintf(3) functions, and which additionally adjusts the code to correctly take into account the return value of vsnprintf(3) and snprintf(3).


Update the affected packages.

Plugin Details

Severity: High

ID: 14017

File Name: mandrake_MDKSA-2003-033.nasl

Version: $Revision: 1.16 $

Type: local

Published: 2004/07/31

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:zlib, p-cpe:/a:mandriva:linux:zlib-devel, p-cpe:/a:mandriva:linux:zlib1, p-cpe:/a:mandriva:linux:zlib1-devel, cpe:/o:mandrakesoft:mandrake_linux:7.2, cpe:/o:mandrakesoft:mandrake_linux:8.0, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2003/03/18

Reference Information

CVE: CVE-2003-0107

BID: 6913

MDKSA: 2003:033