Headline
CVE-2005-1849: Debian -- Security Information -- DSA-763-1 zlib
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.
Markus Oberhumer discovered a flaw in the way zlib, a library used for file compression and decompression, handles invalid input. This flaw can cause programs which use zlib to crash when opening an invalid file.
This problem does not affect the old stable distribution (woody).
For the current stable distribution (sarge), this problem has been fixed in version 1.2.2-4.sarge.2.
For the unstable distribution (sid), this problem has been fixed in version 1.2.3-1.
We recommend that you upgrade your zlib package.