CVE-2022-37434

NameCVE-2022-37434
Descriptionzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3103-1, DSA-5218-1
Debian Bugs1016710

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libz-mingw-w64 (PTS)buster, bullseye1.2.11+dfsg-2vulnerable
bookworm, sid1.2.13+dfsg-1fixed
zlib (PTS)buster1:1.2.11.dfsg-1+deb10u1vulnerable
buster (security)1:1.2.11.dfsg-1+deb10u2fixed
bullseye (security), bullseye1:1.2.11.dfsg-2+deb11u2fixed
bookworm, sid1:1.2.13.dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libz-mingw-w64source(unstable)1.2.12+dfsg-2
zlibsourcebuster1:1.2.11.dfsg-1+deb10u2DLA-3103-1
zlibsourcebullseye1:1.2.11.dfsg-2+deb11u2DSA-5218-1
zlibsource(unstable)1:1.2.11.dfsg-4.11016710

Notes

[bullseye] - libz-mingw-w64 <no-dsa> (Minor issue)
[buster] - libz-mingw-w64 <no-dsa> (Minor issue)
https://github.com/ivd38/zlib_overflow
https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d

Search for package or bug name: Reporting problems