CVE-2002-0059
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.69% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- zlib/zlib
- Source
- cve@mitre.org
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-015.1.txtBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000469Broken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:022Broken Link
- http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txtBroken Link
- http://www.cert.org/advisories/CA-2002-07.htmlThird Party Advisory, US Government Resource
- http://www.debian.org/security/2002/dsa-122Broken Link
- http://www.kb.cert.org/vuls/id/368819Third Party Advisory, US Government Resource
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-023.phpBroken Link, Patch, Vendor Advisory
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-026.htmlBroken Link, Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-027.htmlBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4267Broken Link, Third Party Advisory, VDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-030Broken Link
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-036Broken Link
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-037Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8427Third Party Advisory, VDB Entry
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-015.1.txtBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000469Broken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:022Broken Link
- http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txtBroken Link
- http://www.cert.org/advisories/CA-2002-07.htmlThird Party Advisory, US Government Resource
- http://www.debian.org/security/2002/dsa-122Broken Link
- http://www.kb.cert.org/vuls/id/368819Third Party Advisory, US Government Resource
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-023.phpBroken Link, Patch, Vendor Advisory
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3Broken Link
- http://www.redhat.com/support/errata/RHSA-2002-026.htmlBroken Link, Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-027.htmlBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4267Broken Link, Third Party Advisory, VDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-030Broken Link
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-036Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.