cbcvebase.
CVE-2018-25032
published 2022-03-25

CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
52.06%
98.8th percentile
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Affected

95 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2018-25032 is triggered during deflate (compression) operations in zlib when the input contains many distant matches, leading to memory corruption. Detection should focus on zlib versions prior to 1.2.12 performing deflate operations.
  • The vulnerability was discovered by Danilo Ramos and specifically involves incorrect memory handling during certain deflating operations, which could lead to crash or arbitrary code execution in affected applications.
  • ·The vulnerability is scoped as local exploitation per Debian's tracker, but Oracle's advisories classify it as remotely exploitable via HTTP — detection posture should account for both local and network-facing zlib usage.
  • ·Oracle rates this as remotely exploitable (CVSS 7.5) over HTTP in products such as Siebel CRM and Oracle Communications, meaning network-facing services using vulnerable zlib should be prioritized for patching and monitoring.
  • ·Debian bullseye remains open/unpatched for this CVE; environments running bullseye with zlib should be flagged as unresolved.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.