7.5

CVE-2018-25032

Exploit
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nokogiri ≫ Nokogiri SwPlatform ruby Version < 1.13.4
Python ≫ Python Version >= 3.7.0 < 3.7.14
   Microsoft ≫ Windows Version -
Python ≫ Python Version >= 3.8.0 < 3.8.14
   Microsoft ≫ Windows Version -
Python ≫ Python Version >= 3.9.0 < 3.9.13
   Microsoft ≫ Windows Version -
Python ≫ Python Version >= 3.10.0 < 3.10.5
   Microsoft ≫ Windows Version -
Zlib ≫ Zlib Version >= 1.2.2.2 < 1.2.12
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Apple ≫ macOS X Version >= 10.15 < 10.15.7
Apple ≫ macOS X Version 10.15.7 Update -
Apple ≫ macOS X Version 10.15.7 Update security_update_2020
Apple ≫ macOS X Version 10.15.7 Update security_update_2020-001
Apple ≫ macOS X Version 10.15.7 Update security_update_2020-005
Apple ≫ macOS X Version 10.15.7 Update security_update_2020-007
Apple ≫ macOS X Version 10.15.7 Update security_update_2021-001
Apple ≫ macOS X Version 10.15.7 Update security_update_2021-002
Apple ≫ macOS X Version 10.15.7 Update security_update_2021-003
Apple ≫ macOS X Version 10.15.7 Update security_update_2021-006
Apple ≫ macOS X Version 10.15.7 Update security_update_2021-007
Apple ≫ macOS X Version 10.15.7 Update security_update_2021-008
Apple ≫ macOS X Version 10.15.7 Update security_update_2022-001
Apple ≫ macOS X Version 10.15.7 Update security_update_2022-002
Apple ≫ macOS X Version 10.15.7 Update security_update_2022-003
Apple ≫ macOS Version >= 11.0 < 11.6.6
Apple ≫ macOS Version >= 12.0.0 < 12.4
Mariadb ≫ Mariadb Version >= 10.3.0 < 10.3.36
Mariadb ≫ Mariadb Version >= 10.4.0 < 10.4.26
Mariadb ≫ Mariadb Version >= 10.5.0 < 10.5.17
Mariadb ≫ Mariadb Version >= 10.6.0 < 10.6.9
Mariadb ≫ Mariadb Version >= 10.7.0 < 10.7.5
Mariadb ≫ Mariadb Version >= 10.8.0 < 10.8.4
Mariadb ≫ Mariadb Version >= 10.9.0 < 10.9.2
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ E-series Santricity Os Controller Version >= 11.0.0 <= 11.70.2
Netapp ≫ Hci Compute Node Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Siemens ≫ Scalance Sc622-2c Firmware Version < 3.0
   Siemens ≫ Scalance Sc622-2c Version -
Siemens ≫ Scalance Sc626-2c Firmware Version < 3.0
   Siemens ≫ Scalance Sc626-2c Version -
Siemens ≫ Scalance Sc632-2c Firmware Version < 3.0
   Siemens ≫ Scalance Sc632-2c Version -
Siemens ≫ Scalance Sc636-2c Firmware Version < 3.0
   Siemens ≫ Scalance Sc636-2c Version -
Siemens ≫ Scalance Sc642-2c Firmware Version < 3.0
   Siemens ≫ Scalance Sc642-2c Version -
Siemens ≫ Scalance Sc646-2c Firmware Version < 3.0
   Siemens ≫ Scalance Sc646-2c Version -
Azul ≫ Zulu Version 6.45
Azul ≫ Zulu Version 7.52
Azul ≫ Zulu Version 8.60
Azul ≫ Zulu Version 11.54
Azul ≫ Zulu Version 13.46
Azul ≫ Zulu Version 15.38
Azul ≫ Zulu Version 17.32
Goto ≫ Gotoassist Version < 11.9.18
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 51.73% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20220729-0004/
Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/03/25/2
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2022/03/26/1
Third Party Advisory
Exploit
Mailing List
https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
Third Party Advisory
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
Patch
Third Party Advisory
https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
Patch
Third Party Advisory
https://github.com/madler/zlib/issues/605
Patch
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202210-42
Third Party Advisory
https://security.netapp.com/advisory/ntap-20220526-0009/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5111
Patch
Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/03/24/1
Third Party Advisory
Mailing List
https://www.openwall.com/lists/oss-security/2022/03/28/1
Third Party Advisory
Exploit
Mailing List
https://www.openwall.com/lists/oss-security/2022/03/28/3
Third Party Advisory
Mailing List
https://cert-portal.siemens.com/productcert/html/ssa-398330.html
https://cert-portal.siemens.com/productcert/html/ssa-470355.html
http://seclists.org/fulldisclosure/2022/May/33
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/May/35
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2022/May/38
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
Third Party Advisory
https://support.apple.com/kb/HT213255
Third Party Advisory
https://support.apple.com/kb/HT213256
Third Party Advisory
https://support.apple.com/kb/HT213257
Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-333517.html
https://cert-portal.siemens.com/productcert/html/ssa-419740.html
https://cert-portal.siemens.com/productcert/html/ssa-565386.html
https://cert-portal.siemens.com/productcert/html/ssa-942865.html