UBUNTU-CVE-2022-37434
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-37434
UBUNTU-CVE-2022-37434
Summary:
Details: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
References: https://ubuntu.com/security/CVE-2022-37434, https://github.com/ivd38/zlib_overflow, https://ubuntu.com/security/notices/USN-5570-1, https://ubuntu.com/security/notices/USN-5573-1, https://ubuntu.com/security/notices/USN-5570-2, https://www.cve.org/CVERecord?id=CVE-2022-37434, https://ubuntu.com/security/notices/USN-6736-1, https://ubuntu.com/security/notices/USN-6736-2
Affected packages
Package
Name: klibc
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
