| |
| | [No title] (Site not responding. Last check: 2007-10-22) |
 | | Applications linking statically with zlib 1.1.3 or earlier, or using their own copy of zlib, must be recompiled even if you think your system protects you from double frees. |
 | | Early versions of zlib up to 1.0.8 do not have this double free problem, but have other problems that are fixed in later versions, so these early versions must be upgraded as well. |
 | | This led to the release of zlib 1.1.4 on March 11, 2002 to eliminate the vulnerability, and the release by Jeffrey Lanza of CERT Advisory CA-2002-07 on March 12, 2002. |
| www.gzip.org /zlib/advisory-2002-03-11.txt (538 words) |
|