CPANSA-cppAdaptive1-2018-25032-zlib: cppAdaptive1 vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2022-03-25T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2022-03-25T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 7.5 | Severity | High |
Original language | Language | en | |
Also referred to |
Vulnerability Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Vulnerabilities
CVE-2018-25032
Vulnerability Descriptionzlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Weakness | CWE-787 : Out-of-bounds Write |
---|
Product status
Known affected
Product | Score | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cppAdaptive1 equal =0.01 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-cppAdaptive1-2018-25032-zlib JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2022/cpansa-cppadaptive1-2018-25032-zlib.json - https://rt.cpan.org/Ticket/Display.html?id=143579 external
https://rt.cpan.org/Ticket/Display.html?id=143579 - https://www.openwall.com/lists/oss-security/2022/03/24/1 external
https://www.openwall.com/lists/oss-security/2022/03/24/1 - https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531 external
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531 - http://www.openwall.com/lists/oss-security/2022/03/25/2 external
http://www.openwall.com/lists/oss-security/2022/03/25/2 - http://www.openwall.com/lists/oss-security/2022/03/26/1 external
http://www.openwall.com/lists/oss-security/2022/03/26/1 - https://www.openwall.com/lists/oss-security/2022/03/28/1 external
https://www.openwall.com/lists/oss-security/2022/03/28/1 - https://github.com/madler/zlib/compare/v1.2.11...v1.2.12 external
https://github.com/madler/zlib/compare/v1.2.11...v1.2.12 - https://www.openwall.com/lists/oss-security/2022/03/28/3 external
https://www.openwall.com/lists/oss-security/2022/03/28/3 - https://github.com/madler/zlib/issues/605 external
https://github.com/madler/zlib/issues/605 - https://www.debian.org/security/2022/dsa-5111 external
https://www.debian.org/security/2022/dsa-5111 - https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html external
https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/ - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/ - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/ - https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html external
https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html - https://support.apple.com/kb/HT213255 external
https://support.apple.com/kb/HT213255 - https://support.apple.com/kb/HT213256 external
https://support.apple.com/kb/HT213256 - https://support.apple.com/kb/HT213257 external
https://support.apple.com/kb/HT213257 - http://seclists.org/fulldisclosure/2022/May/33 external
http://seclists.org/fulldisclosure/2022/May/33 - http://seclists.org/fulldisclosure/2022/May/35 external
http://seclists.org/fulldisclosure/2022/May/35 - http://seclists.org/fulldisclosure/2022/May/38 external
http://seclists.org/fulldisclosure/2022/May/38 - https://security.netapp.com/advisory/ntap-20220526-0009/ external
https://security.netapp.com/advisory/ntap-20220526-0009/ - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/ - CVE-2018-25032 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2018-25032
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Fri Mar 25 00:00:00 2022 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/