CVE-2022-37434
🔴 Łataj teraz
Przepełnienie bufora w zlib umożliwia zdalne odczytanie pamięci.
CVSS
9.8
EPSS
16.0%
Exploit
poc
Vendor
netapp
Opis źródłowy (NVD)
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
buffer-overflow exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 16.0% |
| Opublikowano (NVD) | 2022-08-05 07:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-14 12:16:47 UTC |
Referencje
- http://seclists.org/fulldisclosure/2022/Oct/37 (cve@mitre.org) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2022/Oct/38 (cve@mitre.org) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2022/Oct/41 (cve@mitre.org) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2022/Oct/42 (cve@mitre.org) [Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2022/08/05/2 (cve@mitre.org) [Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2022/08/09/1 (cve@mitre.org) [Mailing List, Patch, Third Party Advisory]
- https://github.com/curl/curl/issues/9271 (cve@mitre.org) [Exploit, Issue Tracking, Third Party Advisory]
- https://github.com/ivd38/zlib_overflow (cve@mitre.org) [Exploit, Third Party Advisory]
- https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063 (cve@mitre.org) [Exploit, Third Party Advisory]
- https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d (cve@mitre.org)
- https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1 (cve@mitre.org) [Patch, Third Party Advisory]
- https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764 (cve@mitre.org) [Exploit, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/ (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/ (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/ (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/ (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/ (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20220901-0005/ (cve@mitre.org) [Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20230427-0007/ (cve@mitre.org) [Third Party Advisory]
- https://support.apple.com/kb/HT213488 (cve@mitre.org) [Third Party Advisory]
- https://support.apple.com/kb/HT213489 (cve@mitre.org) [Third Party Advisory]
- https://support.apple.com/kb/HT213490 (cve@mitre.org) [Third Party Advisory]
- https://support.apple.com/kb/HT213491 (cve@mitre.org) [Third Party Advisory]
- https://support.apple.com/kb/HT213493 (cve@mitre.org) [Third Party Advisory]
- https://support.apple.com/kb/HT213494 (cve@mitre.org) [Third Party Advisory]
- https://www.debian.org/security/2022/dsa-5218 (cve@mitre.org) [Third Party Advisory]
- https://cert-portal.siemens.com/productcert/html/ssa-150063.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
- https://cert-portal.siemens.com/productcert/html/ssa-202008.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
- https://cert-portal.siemens.com/productcert/html/ssa-470355.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
- https://cert-portal.siemens.com/productcert/html/ssa-561322.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)