CVE-2018-25032

Name
CVE-2018-25032
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.openwall.com/lists/oss-security/2022/03/24/1
MISC https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
MLIST http://www.openwall.com/lists/oss-security/2022/03/25/2
MLIST http://www.openwall.com/lists/oss-security/2022/03/26/1
MISC https://www.openwall.com/lists/oss-security/2022/03/28/1
CONFIRM https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
MISC https://www.openwall.com/lists/oss-security/2022/03/28/3
MISC https://github.com/madler/zlib/issues/605
DEBIAN https://www.debian.org/security/2022/dsa-5111
MLIST https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
Mailing List http://seclists.org/fulldisclosure/2022/May/33
Mailing List http://seclists.org/fulldisclosure/2022/May/35
Mailing List http://seclists.org/fulldisclosure/2022/May/38
Third Party Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
Mailing List https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
Mailing List https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
Third Party Advisory https://security.gentoo.org/glsa/202210-42
Third Party Advisory https://security.netapp.com/advisory/ntap-20220526-0009/
Third Party Advisory https://security.netapp.com/advisory/ntap-20220729-0004/
Third Party Advisory https://support.apple.com/kb/HT213255
Third Party Advisory https://support.apple.com/kb/HT213256
Third Party Advisory https://support.apple.com/kb/HT213257
Patch https://www.oracle.com/security-alerts/cpujul2022.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:* zlib >= None < 1.2.12
cpe:2.3:a:nokogiri:nokogiri:*:*:*:*:*:ruby:*:* ruby-nokogiri >= None < 1.13.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
minizip 3.15-community 1.2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
minizip 3.16-community 1.2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
mariadb 3.13-main 10.5.17-r0 Natanael Copa <ncopa@alpinelinux.org> fixed