
CVE-2022-37434
- Reference to the description:
- Description:
- zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
- Last updated date:
- 07/19/2023
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 08/11/2022
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 08/11/2022
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 08/11/2022
- Reference url to background
https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 08/11/2022
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 10/15/2022
- Reference url to background