Re: zlib on Solaris?

From: Scott Howard (scott@doc.net.au)
Date: 03/16/02


Date: Sat, 16 Mar 2002 20:31:05 +1100
From: Scott Howard <scott@doc.net.au>
To: Kalle Andersson <kan@virus112.com>

On Tue, Mar 12, 2002 at 01:08:52PM +0100, Kalle Andersson wrote:
> Quick question, any info on if zlib can or can't cause problem on a solaris
> system?
> I haven't been able to find a yes or no on that question, just that the
> problem is primarily on Linux.

The short answer is "possibly".

Casper *** write the following on Bugtraq earlier today :

"Furthermore, it appears that our libc's malloc catches double frees
in several ways; that may also lower the risk somewhat."
(Full msg at
http://msgs.securepoint.com/cgi-bin/get/bugtraq0203/139/1/1/1/1/1/1.html)

As far as I'm aware there are no exploits for this problem available for
any programs on any platforms yet, but that doesn't mean there wont be...

  Scott