Re: Buffer overflow in zlib

2005-07-10 Thread Ken Moffat
On Sun, 10 Jul 2005, Jeremy Henty wrote: > > On Sat, Jul 09, 2005 at 10:35:41PM +0100, Ken Moffat wrote: > > > On my 6.1-testing system, _nothing_ shows except rsync's modified > > version of zlib. > > OT, *why* does rsync do this? I've Googled lots of discussions about > making gzip rsync-friend

Re: Buffer overflow in zlib

2005-07-09 Thread Jeremy Henty
On Sat, Jul 09, 2005 at 10:35:41PM +0100, Ken Moffat wrote: > On my 6.1-testing system, _nothing_ shows except rsync's modified > version of zlib. OT, *why* does rsync do this? I've Googled lots of discussions about making gzip rsync-friendly but it's not clear if this has been implemented, or

Re: Buffer overflow in zlib

2005-07-09 Thread Ken Moffat
On Sat, 9 Jul 2005, Dan Osterrath wrote: > > Have a look at http://cert.uni-stuttgart.de/files/fw/find-zlib > This perl script searches for programs statically linked against zlib. > Thanks for the reminder, Dan. On my 6.1-testing system, _nothing_ shows except rsync's modified version of zlib

Re: Buffer overflow in zlib

2005-07-09 Thread Dan Osterrath
José Carlos Carrión Plaza schrieb: > The question is: > > The zlib library is compiled in static and shared forms. Once it will be > updated, the shared versions will be accessible inmediately. But, the > programs compiled against the static version of this library remained > with the old (and vul

Re: Buffer overflow in zlib

2005-07-09 Thread Ken Moffat
On Sat, 9 Jul 2005, [ISO-8859-1] José Carlos Carrión Plaza wrote: > Dear list members: > > Anyone knows about the gentoo linux security advisor labeled «GLSA > 200507-05 / zlib»? > Hopefully, that's the same one that archaic posted a patch for on lfs-security earlier this week (i.e. fixed in 6.1-

Re: Buffer overflow in zlib

2005-07-09 Thread Matthew Burgess
José Carlos Carrión Plaza wrote: Dear list members: Anyone knows about the gentoo linux security advisor labeled «GLSA 200507-05 / zlib»? Yep, we've fixed this in LFS-6.1-pre2 and also the devlopment (trunk) version of the book. But which are the programs of LFS and BLFS that are been co

Buffer overflow in zlib

2005-07-09 Thread José Carlos Carrión Plaza
Dear list members: Anyone knows about the gentoo linux security advisor labeled «GLSA 200507-05 / zlib»? (More information can be founded at http://www.gentoo.org/security/en/glsa/glsa-200507-05.xml ) The problem is a buffer overflow in zlib that permits the execution of arbitrary code in