CVE-2003-0107 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 26% (pctl 98)
Patch early
A public exploit exists.
Description
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 25.99% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-03-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| zlib | zlib |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Zlib 1.1.4 - Compression Library 'gzprintf()' Buffer Overrun (1) | 2003-02-23 |
| exploit-db | Zlib 1.1.4 - Compression Library 'gzprintf()' Buffer Overrun (2) | 2003-02-23 |
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc
- http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000619
- http://jvn.jp/en/jp/JVN78689801/index.html
- http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000066.html
- http://lists.apple.com/mhonarc/security-announce/msg00038.html
- http://marc.info/?l=bugtraq&m=104610337726297&w=2
- http://marc.info/?l=bugtraq&m=104610536129508&w=2
- http://marc.info/?l=bugtraq&m=104620610427210&w=2
- http://marc.info/?l=bugtraq&m=104887247624907&w=2
- http://online.securityfocus.com/archive/1/312869
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405
- http://www.iss.net/security_center/static/11381.php
- http://www.kb.cert.org/vuls/id/142121
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033
- http://www.osvdb.org/6599
- http://www.redhat.com/support/errata/RHSA-2003-079.html
- http://www.redhat.com/support/errata/RHSA-2003-081.html
- http://www.securityfocus.com/bid/6913
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt
→ the Explorer · watch your stack · NVD