Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz
ID: 7374c669-3087-5097-848b-19f938ec8abb
STIX ID: report--7374c669-3087-5097-848b-19f938ec8abb
Feed Name: cybersecurityNews.com
**Executive Summary:** A global buffer overflow vulnerability in the zlib untgz utility v1.3.1.2 stems from an unbounded strcpy() in TGZfname() that copies command-line archive names into a fixed 1,024-byte global buffer, enabling denial-of-service, memory corruption, and potentially arbitrary code execution; researchers demonstrated the issue with AddressSanitizer showing a 2,001-byte out-of-bounds write when invoked with a 4,096-byte filename, and no CVE has yet been assigned.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
