VulnerabilityModified
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
HIGH 7.5EPSS 51.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 51.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 51.73% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- nokogiri/nokogiri · python/python · zlib/zlib · debian/debian linux · fedoraproject/fedora · apple/mac os x · apple/macos · mariadb/mariadb · netapp/active iq unified manager · netapp/e-series santricity os controller · netapp/management services for element software · netapp/oncommand workflow automation · netapp/ontap select deploy administration utility · netapp/hci compute node · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · netapp/h410c firmware · siemens/scalance sc622-2c firmware · +7 more
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2022/May/33Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/03/25/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/03/26/1Exploit, Mailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdfThird Party Advisory
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531Patch, Third Party Advisory
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12Patch, Third Party Advisory
- https://github.com/madler/zlib/issues/605Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/04/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00008.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/Third Party Advisory
- https://security.gentoo.org/glsa/202210-42Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220526-0009/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220729-0004/Third Party Advisory
- https://support.apple.com/kb/HT213255Third Party Advisory
- https://support.apple.com/kb/HT213256Third Party Advisory
- https://support.apple.com/kb/HT213257Third Party Advisory
- https://www.debian.org/security/2022/dsa-5111Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/24/1Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/28/1Exploit, Mailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/28/3Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/33Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.