logo

Critical zlib Flaw Let Attackers Can Trigger a Buffer Overflow via untgz

ID: fd425c09-01ed-5acb-80c9-1519dc4b8cdc

STIX ID: report--fd425c09-01ed-5acb-80c9-1519dc4b8cdc

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Divya

...
...

A severe global buffer overflow was identified in the zlib untgz utility (version 1.3.1.2) where TGZfname() uses strcpy() to copy an argv-supplied archive name into a fixed 1024-byte global buffer without bounds checking. Security researchers reproduced the issue with AddressSanitizer using a 4096-byte input (ASAN reported a 2001-byte write), and the flaw is trivially exploitable via a long command-line filename; impacts range from crashes and memory corruption to potential arbitrary code execution depending on build and runtime conditions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.