>> OpenPKG Security Update Fixes CVS Denial of Service Vulnerability
Title : OpenPKG Security Update Fixes CVS Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2005-0746 CVE ID : CVE-2004-0797 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-13
Technical Description
OpenPKG has released a security patch to correct a vulnerability identified in Concurrent Versions Systems (CVS). This flaw resides in the "inflate()" and "inflateBack()" functions of the zlib compression library that fails to handle certain error conditions properly, which may be exploited by an attacker to cause a denial of service.