[24678] in bugtraq
Re: [RHSA-2002:026-35] Vulnerability in zlib library
daemon@ATHENA.MIT.EDU (Tomasz Ostrowski)
Wed Mar 13 21:59:07 2002
Date: Wed, 13 Mar 2002 12:04:19 +0100
From: Tomasz Ostrowski <tometzky@batory.org.pl>
To: bugtraq@securityfocus.com
Cc: linux-security@redhat.com
Message-ID: <20020313110419.GB12453@batory.org.pl>
Reply-To: bugtraq@securityfocus.com
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.LNX.4.44.0203121322260.29551-100000@debussy.ucsc.edu>
It seems that RedHat in its "Vulnerability in zlib library" advisory [1]
has forgotten to write that a "rpm" program is staticly linked with zlib
and needs to be recompiled.
I have used find-zlib perl script [2] (linked from the zlib homepage [3])
to find out which programs use staticly linked zlib and got the
following output on "rpm" binary:
| rpm: inflate version: "1.1.3 Copyright 1995-1998 Mark Adler"
| rpm: zlib cplens table, little endian
| rpm: zlib cplext table (version 1.0.5 to 1.1.4)
[1] http://www.redhat.com/support/errata/RHSA-2002-026.html
I think it was never posted to BugTraq
[2] http://cert.uni-stuttgart.de/files/fw/find-zlib
find-zlib - scan for zlib tables in compiled code
Copyright (C) 2002 RUS-CERT, University of Stuttgart.
Written by Florian Weimer <Weimer@CERT.Uni-Stuttgart.DE>.
[3] http://www.gzip.org/zlib/
Sorry for my English...
--
Best wishes ...although Eating Honey was a very good thing to do,
Tometzky there was a moment just before you began to eat it
which was better than when you were...
Winnie the Pooh