Lucene search

K
cloudlinuxCloudLinuxCLSA-2022:1660762053
HistoryAug 17, 2022 - 6:47 p.m.

Fixed CVE-2022-37434 in zlib

2022-08-1718:47:33
repo.cloudlinux.com
171
cve-2022-37434
zlib
buffer overflow
gzip header
unix

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

71.6%

  • CVE-2022-37434: fix possible buffer overflow when getting a gzip header extra field
    with inflate()

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

71.6%