CVE-2018-25032

Name
CVE-2018-25032
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.openwall.com/lists/oss-security/2022/03/24/1
MISC https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
MLIST http://www.openwall.com/lists/oss-security/2022/03/25/2
MLIST http://www.openwall.com/lists/oss-security/2022/03/26/1
MISC https://www.openwall.com/lists/oss-security/2022/03/28/1
CONFIRM https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
MISC https://www.openwall.com/lists/oss-security/2022/03/28/3
MISC https://github.com/madler/zlib/issues/605
DEBIAN https://www.debian.org/security/2022/dsa-5111
MLIST https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
Mailing List http://seclists.org/fulldisclosure/2022/May/33
Mailing List http://seclists.org/fulldisclosure/2022/May/35
Mailing List http://seclists.org/fulldisclosure/2022/May/38
Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
Mailing List https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
Mailing List https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
Third Party Advisory https://security.gentoo.org/glsa/202210-42
Third Party Advisory https://security.netapp.com/advisory/ntap-20220526-0009/
Third Party Advisory https://security.netapp.com/advisory/ntap-20220729-0004/
Third Party Advisory https://support.apple.com/kb/HT213255
Third Party Advisory https://support.apple.com/kb/HT213256
Third Party Advisory https://support.apple.com/kb/HT213257
Patch https://www.oracle.com/security-alerts/cpujul2022.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-333517.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-398330.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-419740.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-470355.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-565386.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-942865.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:* zlib >= None < 1.2.12
cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:* ruby-nokogiri >= None < 1.13.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
zlib edge-main 1.2.11-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
zlib 3.22-main 1.2.11-r4 None fixed
zlib 3.21-main 1.2.11-r4 None fixed
zlib 3.20-main 1.2.11-r4 None fixed
zlib 3.19-main 1.2.11-r4 None fixed
zlib 3.18-main 1.2.11-r4 None fixed
zlib 3.17-main 1.2.11-r4 None fixed
zlib 3.12-main 1.2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
ruby-nokogiri edge-community 1.11.6-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
ruby-nokogiri edge-community 1.10.4-r0 None fixed
ruby-nokogiri 3.22-community 1.11.6-r0 None fixed
ruby-nokogiri 3.22-community 1.10.4-r0 None fixed
minizip edge-community 1.2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
minizip 3.22-community 1.2.12-r0 None fixed
minizip 3.21-community 1.2.12-r0 None fixed
minizip 3.20-community 1.2.12-r0 None fixed
minizip 3.19-community 1.2.12-r0 None fixed
minizip 3.18-community 1.2.12-r0 None fixed
minizip 3.17-community 1.2.12-r0 None fixed
mariadb edge-main 10.6.9-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mariadb 3.22-main 10.6.9-r0 None fixed
mariadb 3.21-main 10.6.9-r0 None fixed
mariadb 3.20-main 10.6.9-r0 None fixed
mariadb 3.19-main 10.6.9-r0 None fixed
mariadb 3.18-main 10.6.9-r0 None fixed
mariadb 3.17-main 10.6.9-r0 None fixed