SUSE-SA:2005:043: zlib

High Nessus Plugin ID 19333


The remote host is missing a vendor-supplied security patch


The remote host is missing the patch for the advisory SUSE-SA:2005:043 (zlib).

The previous zlib update for CVE-2005-2096 fixed a flaw in zlib that could allow a carefully crafted compressed stream to crash an application. While the original patch corrected the reported overflow, Markus Oberhumer discovered additional ways a stream could trigger an overflow. This update fixes those problems as well.

This issue is tracked by the Mitre CVE ID CVE-2005-1849.

Since only zlib 1.2.x is affected, older SUSE products are not affected by this problem.


Plugin Details

Severity: High

ID: 19333

File Name: suse_SA_2005_043.nasl

Version: $Revision: 1.5 $

Agent: unix

Published: 2005/07/31

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

Required KB Items: Host/SuSE/rpm-list