Back to search
CVE-2022-37434
Published: Aug 5, 2022
Modified: May 30, 2025
PUBLISHED
Description
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | unknown n/a |
References
[oss-security] 20220805 zlib buffer overflow
mailing-list
[oss-security] 20220808 Re: zlib buffer overflow
mailing-list
FEDORA-2022-25e4dbedf9
vendor-advisory
DSA-5218
vendor-advisory
FEDORA-2022-15da0cf165
vendor-advisory
FEDORA-2022-b8232d1cca
vendor-advisory
FEDORA-2022-3c28ae0cd8
vendor-advisory
FEDORA-2022-0b517a5397
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now