CVE-2022-37434

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zlibzlib
𝑥
≤ 1.2.12
debiandebian_linux
10.0
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netapphci
-
netappmanagement_services_for_element_software
-
netapponcommand_workflow_automation
-
netappontap_select_deploy_administration_utility
-
netappstoragegrid
-
netapphci_compute_node
-
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph700s_firmware
-
appleipados
𝑥
< 15.7.1
appleiphone_os
𝑥
< 15.7.1
appleiphone_os
16.0 ≤
𝑥
< 16.1
applemacos
11.0 ≤
𝑥
< 11.7.1
applemacos
12.0.0 ≤
𝑥
< 12.6.1
applewatchos
𝑥
< 9.1
stormshieldstormshield_network_security
3.7.31 ≤
𝑥
< 3.7.34
stormshieldstormshield_network_security
3.11.0 ≤
𝑥
< 3.11.22
stormshieldstormshield_network_security
4.3.0 ≤
𝑥
< 4.3.16
stormshieldstormshield_network_security
4.6.0 ≤
𝑥
< 4.6.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libz-mingw-w64
bullseye
no-dsa
buster
no-dsa
bookworm
1.2.13+dfsg-1
fixed
sid
1.3.1+dfsg-1
fixed
trixie
1.3.1+dfsg-1
fixed
zlib
bullseye (security)
1:1.2.11.dfsg-2+deb11u2
fixed
bullseye
1:1.2.11.dfsg-2+deb11u2
no-dsa
buster
no-dsa
bookworm
1:1.2.13.dfsg-1
fixed
sid
1:1.3.dfsg+really1.3.1-1
fixed
trixie
1:1.3.dfsg+really1.3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
klibc
noble
Fixed 2.0.13-4ubuntu0.1
released
mantic
Fixed 2.0.13-1ubuntu0.1
released
jammy
Fixed 2.0.10-4ubuntu0.1
released
focal
Fixed 2.0.7-1ubuntu5.2
released
bionic
Fixed 2.0.4-9ubuntu2.2+esm1
released
xenial
Fixed 2.0.4-8ubuntu1.16.04.4+esm2
released
trusty
Fixed 2.0.3-0ubuntu1.14.04.3+esm3
released
rsync
noble
not-affected
mantic
not-affected
kinetic
not-affected
jammy
not-affected
focal
Fixed 3.1.3-8ubuntu0.4
released
bionic
Fixed 3.1.2-2.1ubuntu1.5
released
xenial
Fixed 3.1.1-3ubuntu1.3+esm2
released
trusty
not-affected
zlib
noble
not-affected
mantic
not-affected
kinetic
not-affected
jammy
Fixed 1:1.2.11.dfsg-2ubuntu9.2
released
focal
Fixed 1:1.2.11.dfsg-2ubuntu1.5
released
bionic
Fixed 1:1.2.11.dfsg-0ubuntu2.2
released
xenial
Fixed 1:1.2.8.dfsg-2ubuntu4.3+esm2
released
trusty
Fixed 1:1.2.8.dfsg-1ubuntu1.1+esm2
released
References