DSA-797-2

    Dashboard / Vulnerabilities / DSA-797-2

    DSA-797-2

    Published: 1 Sept 2005Last Modified: 4 Jul 2022

    Summary: zsync - buffer overflow

    Details: zsync, a file transfer program, includes a modified local copy of the zlib library, and is vulnerable to certain bugs fixed previously in the zlib package. There was a build error for the sarge i386 proftpd packages released in DSA 797-1. A new build, zsync\_0.3.3-1.sarge.1.2, has been prepared to correct this error. The packages for other architectures are unaffected. The old stable distribution (woody) does not contain the zsync package. For the stable distribution (sarge) this problem has been fixed in version 0.3.3-1.sarge.1. For the unstable distribution (sid) this problem has been fixed in version 0.4.0-2. We recommend that you upgrade your zsync package.

    References:

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High