CVE-2018-25032

Name
CVE-2018-25032
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.openwall.com/lists/oss-security/2022/03/24/1
MISC https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
MLIST http://www.openwall.com/lists/oss-security/2022/03/25/2
MLIST http://www.openwall.com/lists/oss-security/2022/03/26/1
MISC https://www.openwall.com/lists/oss-security/2022/03/28/1
CONFIRM https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
MISC https://www.openwall.com/lists/oss-security/2022/03/28/3
MISC https://github.com/madler/zlib/issues/605
DEBIAN https://www.debian.org/security/2022/dsa-5111
MLIST https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:* zlib >= None < 1.2.12

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
minizip 3.15-community 1.2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
minizip 3.16-community 1.2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mariadb 3.14-main 10.5.17-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mariadb 3.13-main 10.5.17-r0 Natanael Copa <ncopa@alpinelinux.org> fixed