zlib 1:1.2.11.dfsg-2ubuntu1.5 source package in Ubuntu

Changelog

zlib (1:1.2.11.dfsg-2ubuntu1.5) focal-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer over-read (LP: #1988548)
    - debian/patches/CVE-2022-37434-1.patch: in inflate.c, add an extra
      condition to check if state->head->extra_max is greater than len
      before copying, and move the len assignment to be placed before the
      check.
    - debian/patches/CVE-2022-37434-2.patch: in the previous patch, in
      inflate.c, the place of the len assignment was causing issues so it
      was moved to be placed within the check.
    - CVE-2022-37434

 -- Rodrigo Figueiredo Zaiden <email address hidden>  Fri, 14 Oct 2022 17:22:43 -0300

Upload details

Uploaded by:
Rodrigo Figueiredo Zaiden
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates main libs
Focal security main libs

Downloads

File Size SHA-256 Checksum
zlib_1.2.11.dfsg.orig.tar.gz 361.6 KiB 80c481411a4fe8463aeb8270149a0e80bb9eaf7da44132b6e16f2b5af01bc899
zlib_1.2.11.dfsg-2ubuntu1.5.debian.tar.xz 55.1 KiB 09b9d80f1c3a02f7019a3991fedf7679a21092c57eaf8eb4bf58eee709b22ef9
zlib_1.2.11.dfsg-2ubuntu1.5.dsc 2.6 KiB 406e60b3c9311249b151a4e784ed3e146413fdb686a129c628da91397bb751f7

View changes file

Binary packages built by this source

lib32z1: compression library - 32 bit runtime

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes a 32 bit version of the
 shared library.

lib32z1-dbgsym: debug symbols for lib32z1
lib32z1-dev: compression library - 32 bit - DO NOT USE EXCEPT FOR PACKAGING

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes the development support
 files for building 32 bit applications.
 .
 This package should ONLY be used for building packages, users who do
 not need to build packages should use multiarch to install the relevant
 runtime.

lib64z1: compression library - 64 bit runtime

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes a 64 bit version of the
 shared library.

lib64z1-dbgsym: debug symbols for lib64z1
lib64z1-dev: compression library - 64 bit - DO NOT USE EXCEPT FOR PACKAGING

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes the development support
 files for building 64 bit applications.
 .
 This package should ONLY be used for building packages, users who do
 not need to build packages should use multiarch to install the relevant
 runtime.

libx32z1: compression library - x32 runtime

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes a n32 version of the shared
 library.

libx32z1-dbgsym: debug symbols for libx32z1
libx32z1-dev: compression library - x32 - DO NOT USE EXCEPT FOR PACKAGING

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes the development support
 files for building n32 applications.
 .
 This package should ONLY be used for building packages, users who do
 not need to build packages should use multiarch to install the relevant
 runtime.

zlib1g: compression library - runtime

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes the shared library.

zlib1g-dbgsym: debug symbols for zlib1g
zlib1g-dev: compression library - development

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This package includes the development support
 files.

zlib1g-udeb: compression library - runtime for Debian installer

 zlib is a library implementing the deflate compression method found
 in gzip and PKZIP. This minimal package includes the shared library
 for use with the Debian installer.