[USN-5355-2] zlib vulnerability

Severity Medium
Affected Packages 17
CVEs 1

zlib could be made to crash or run programs if it received specially crafted input.

USN-5355-1 fixed a vulnerability in zlib. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

Danilo Ramos discovered that zlib incorrectly handled memory when
performing certain deflating operations. An attacker could use this issue
to cause zlib to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Package Affected Version
pkg:deb/ubuntu/zlib1g?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/zlib1g?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/zlib1g-dev?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/zlib1g-dev?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/zlib-bin?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/libx32z1?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/libx32z1?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/libx32z1-dev?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/libx32z1-dev?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/lib64z1?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/lib64z1?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/lib64z1-dev?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/lib64z1-dev?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/lib32z1?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/lib32z1?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
pkg:deb/ubuntu/lib32z1-dev?distro=xenial < 1.2.8.dfsg-2ubuntu4.3+esm1
pkg:deb/ubuntu/lib32z1-dev?distro=trusty < 1.2.8.dfsg-1ubuntu1.1+esm1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/zlib1g?distro=xenial ubuntu zlib1g < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/zlib1g?distro=trusty ubuntu zlib1g < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/zlib1g-dev?distro=xenial ubuntu zlib1g-dev < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/zlib1g-dev?distro=trusty ubuntu zlib1g-dev < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/zlib-bin?distro=trusty ubuntu zlib-bin < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/libx32z1?distro=xenial ubuntu libx32z1 < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/libx32z1?distro=trusty ubuntu libx32z1 < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/libx32z1-dev?distro=xenial ubuntu libx32z1-dev < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/libx32z1-dev?distro=trusty ubuntu libx32z1-dev < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/lib64z1?distro=xenial ubuntu lib64z1 < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/lib64z1?distro=trusty ubuntu lib64z1 < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/lib64z1-dev?distro=xenial ubuntu lib64z1-dev < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/lib64z1-dev?distro=trusty ubuntu lib64z1-dev < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/lib32z1?distro=xenial ubuntu lib32z1 < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/lib32z1?distro=trusty ubuntu lib32z1 < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
Affected pkg:deb/ubuntu/lib32z1-dev?distro=xenial ubuntu lib32z1-dev < 1.2.8.dfsg-2ubuntu4.3+esm1 xenial
Affected pkg:deb/ubuntu/lib32z1-dev?distro=trusty ubuntu lib32z1-dev < 1.2.8.dfsg-1ubuntu1.1+esm1 trusty
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...