CVE-2022-37434

NameCVE-2022-37434
Descriptionzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs1016710

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zlib (PTS)buster1:1.2.11.dfsg-1vulnerable
buster (security)1:1.2.11.dfsg-1+deb10u1vulnerable
bullseye (security), bullseye1:1.2.11.dfsg-2+deb11u1vulnerable
bookworm, sid1:1.2.11.dfsg-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zlibsource(unstable)(unfixed)1016710

Notes

https://github.com/ivd38/zlib_overflow
https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d

Search for package or bug name: Reporting problems