Lucene search

K
freebsdFreeBSDA1323A76-28F1-11ED-A72A-002590C1F29C
HistoryAug 30, 2022 - 12:00 a.m.

FreeBSD -- zlib heap buffer overflow

2022-08-3000:00:00
vuxml.freebsd.org
42
freebsd
zlib
buffer overflow

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

71.7%

Problem Description:
zlib through 1.2.12 has a heap-based buffer over-read or buffer
overflow in inflate in inflate.c via a large gzip header extra
field.
Impact:
Applications that call inflateGetHeader may be vulnerable to a
buffer overflow. Note that inflateGetHeader is not used by anything
in the FreeBSD base system, but may be used by third party
software.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchfreebsd= 13.1UNKNOWN
FreeBSDanynoarchfreebsd< 13.1_2UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

71.7%