Critical zlib Flaw Let Attackers Can Trigger a Buffer Overflow via untgz
ID: fd425c09-01ed-5acb-80c9-1519dc4b8cdc
STIX ID: report--fd425c09-01ed-5acb-80c9-1519dc4b8cdc
Feed Name: GBHackers
A severe global buffer overflow was identified in the zlib untgz utility (version 1.3.1.2) where TGZfname() uses strcpy() to copy an argv-supplied archive name into a fixed 1024-byte global buffer without bounds checking. Security researchers reproduced the issue with AddressSanitizer using a 4096-byte input (ASAN reported a 2001-byte write), and the flaw is trivially exploitable via a long command-line filename; impacts range from crashes and memory corruption to potential arbitrary code execution depending on build and runtime conditions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
