Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libcompress-raw-zlib-perlUpgrade perl | Jul 30, 2024 | Jun 16, 2009 |
| Gentoo Linux | — | Upgrade perl-core/Compress-Raw-Zlib.Upgrade perl-core/Compress-Raw-Bzip2. | Oct 30, 2017 | Jun 16, 2009 |
| Suse | — | Upgrade perl-32bitUpgrade perlUpgrade perl-x86Upgrade perl-docUpgrade perl-base | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade perlUpgrade libcompress-raw-zlib-perl | Nov 8, 2024 | Jun 16, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub