cbcvebase.
CVE-2018-25032
published 2022-03-25

CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Affected

82 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
azulzulu
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlibz-mingw-w64< libz-mingw-w64 1.2.11+dfsg-5 (bookworm)libz-mingw-w64 1.2.11+dfsg-5 (bookworm)
debianzlib< libz-mingw-w64 1.2.11+dfsg-5 (bookworm)libz-mingw-w64 1.2.11+dfsg-5 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gotogotoassist< 11.9.1811.9.18
klibc_projectklibc>= 0 < 2.0.7-1ubuntu5.22.0.7-1ubuntu5.2
klibc_projectklibc>= 0 < 2.0.10-4ubuntu0.12.0.10-4ubuntu0.1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv8.8HIGH