Gentoo Archives: gentoo-announce

From: Alex Legler <a3li@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200908-07 ] Perl Compress::Raw modules: Denial of Service
Date: Tue, 18 Aug 2009 21:49:24
Message-Id: 20090818233723.684ceb2c@neon
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200908-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Perl Compress::Raw modules: Denial of Service
9 Date: August 18, 2009
10 Bugs: #273141, #281955
11 ID: 200908-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 An off-by-one error in Compress::Raw::Zlib and Compress::Raw::Bzip2
19 might lead to a Denial of Service.
20
21 Background
22 ==========
23
24 Compress::Raw::Zlib and Compress::Raw::Bzip2 are Perl low-level
25 interfaces to the zlib and bzip2 compression libraries.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 perl-core/Compress-Raw-Zlib < 2.020 >= 2.020
34 2 perl-core/Compress-Raw-Bzip2 < 2.020 >= 2.020
35 -------------------------------------------------------------------
36 2 affected packages on all of their supported architectures.
37 -------------------------------------------------------------------
38
39 Description
40 ===========
41
42 Leo Bergolth reported an off-by-one error in the inflate() function in
43 Zlib.xs of Compress::Raw::Zlib, possibly leading to a heap-based buffer
44 overflow (CVE-2009-1391).
45
46 Paul Marquess discovered a similar vulnerability in the bzinflate()
47 function in Bzip2.xs of Compress::Raw::Bzip2 (CVE-2009-1884).
48
49 Impact
50 ======
51
52 A remote attacker might entice a user or automated system (for instance
53 running SpamAssassin or AMaViS) to process specially crafted files,
54 possibly resulting in a Denial of Service condition.
55
56 Workaround
57 ==========
58
59 There is no known workaround at this time.
60
61 Resolution
62 ==========
63
64 All Compress::Raw::Zlib users should upgrade to the latest version:
65
66 # emerge --sync
67 # emerge --ask --oneshot --verbose
68 =perl-core/Compress-Raw-Zlib-2.020
69
70 All Compress::Raw::Bzip2 users should upgrade to the latest version:
71
72 # emerge --sync
73 # emerge --ask --oneshot --verbose
74 =perl-core/Compress-Raw-Bzip2-2.020
75
76 References
77 ==========
78
79 [ 1 ] CVE-2009-1391
80 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1391
81 [ 2 ] CVE-2009-1884
82 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1884
83
84 Availability
85 ============
86
87 This GLSA and any updates to it are available for viewing at
88 the Gentoo Security Website:
89
90 http://security.gentoo.org/glsa/glsa-200908-07.xml
91
92 Concerns?
93 =========
94
95 Security is a primary focus of Gentoo Linux and ensuring the
96 confidentiality and security of our users machines is of utmost
97 importance to us. Any security concerns should be addressed to
98 security@g.o or alternatively, you may file a bug at
99 https://bugs.gentoo.org.
100
101 License
102 =======
103
104 Copyright 2009 Gentoo Foundation, Inc; referenced text
105 belongs to its owner(s).
106
107 The contents of this document are licensed under the
108 Creative Commons - Attribution / Share Alike license.
109
110 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature