CVE-2005-2459

Publication date 23 August 2005

Last updated 24 July 2024


Ubuntu priority

The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerability than CVE-2005-2458.

Status

Package Ubuntu Release Status
kernel-source-2.4.27 7.04 feisty Not in release
6.10 edgy
Fixed 2.4.27-12
6.06 LTS dapper
Fixed 2.4.27-12
linux-source-2.6.15 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper
Fixed 2.6.15-29.58
linux-source-2.6.17 7.04 feisty Not in release
6.10 edgy
Fixed 2.6.17.1-12.40
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-169-1
    • Linux kernel vulnerabilities
    • 19 August 2005

Other references