SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-25032

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

HIGH 7.5EPSS 51.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 51.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
51.73% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
nokogiri/nokogiri · python/python · zlib/zlib · debian/debian linux · fedoraproject/fedora · apple/mac os x · apple/macos · mariadb/mariadb · netapp/active iq unified manager · netapp/e-series santricity os controller · netapp/management services for element software · netapp/oncommand workflow automation · netapp/ontap select deploy administration utility · netapp/hci compute node · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · netapp/h410c firmware · siemens/scalance sc622-2c firmware · +7 more
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.