CVE-2022-37434
Summary
| CVE | CVE-2022-37434 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-05 07:15:00 UTC |
| Updated | 2023-07-19 00:56:00 UTC |
| Description | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference). |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Ipados | All | All | All | All |
| Operating System | Apple | Ipad Os | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Macos | All | All | All | All |
| Operating System | Apple | Watchos | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Hardware | Netapp | H300s | - | All | All | All |
| Operating System | Netapp | H300s Firmware | - | All | All | All |
| Hardware | Netapp | H500s | - | All | All | All |
| Operating System | Netapp | H500s Firmware | - | All | All | All |
| Hardware | Netapp | H700s | - | All | All | All |
| Operating System | Netapp | H700s Firmware | - | All | All | All |
| Application | Netapp | Hci | - | All | All | All |
| Hardware | Netapp | Hci Compute Node | - | All | All | All |
| Application | Netapp | Management Services For Element Software | - | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Ontap Select Deploy Administration Utility | - | All | All | All |
| Application | Netapp | Storagegrid | - | All | All | All |
| Application | Stormshield | Stormshield Network Security | All | All | All | All |
| Application | Zlib | Zlib | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: zlib-1.2.12-5.fc37 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| Full Disclosure: APPLE-SA-2022-10-27-5 Additional information for APPLE-SA-2022-10-24-2 macOS Ventura 13 | FULLDISC | seclists.org | |
| [SECURITY] Fedora 35 Update: zlib-1.2.11-32.fc35 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: zlib-1.2.11-33.fc36 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| GitHub - ivd38/zlib_overflow: Program to trigger zlib 1.2.12 buffer overflow | MISC | github.com | |
| [SECURITY] Fedora 35 Update: zlib-1.2.11-32.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Full Disclosure: APPLE-SA-2022-10-27-1 iOS 15.7.1 and iPadOS 15.7.1 | MISC | seclists.org | |
| zlib/zlib.h at 21767c654d31d2dccdde4330529775c6c5fd5389 · madler/zlib · GitHub | MISC | github.com | |
| [SECURITY] Fedora 36 Update: rsync-3.2.5-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Test 224 fails with CVE-2022-37434 patched zlib · Issue #9271 · curl/curl · GitHub | MISC | github.com | |
| [SECURITY] Fedora 35 Update: rsync-3.2.5-1.fc35 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| About the security content of macOS Ventura 13 - Apple Support | CONFIRM | support.apple.com | |
| CVE-2022-37434 Zlib Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Full Disclosure: APPLE-SA-2022-10-27-2 Additional information for APPLE-SA-2022-10-24-1 iOS 16.1 and iPadOS 16 | MISC | seclists.org | |
| April 2023 MySQL Server Vulnerabilities in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| [SECURITY] [DLA 3103-1] zlib security update | MLIST | lists.debian.org | |
| Full Disclosure: APPLE-SA-2022-10-27-6 Additional information for APPLE-SA-2022-10-24-3 macOS Monterey 12.6.1 | MISC | seclists.org | |
| Fix a bug when getting a gzip header extra field with inflate(). · madler/zlib@eff308a · GitHub | MISC | github.com | |
| About the security content of iOS 16.1 and iPadOS 16 - Apple Support | CONFIRM | support.apple.com | |
| [SECURITY] Fedora 35 Update: rsync-3.2.5-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| oss-security - zlib buffer overflow | MLIST | www.openwall.com | |
| About the security content of macOS Big Sur 11.7.1 - Apple Support | CONFIRM | support.apple.com | |
| About the security content of macOS Monterey 12.6.1 - Apple Support | CONFIRM | support.apple.com | |
| node/inflate.c at 75b68c6e4db515f76df73af476eccf382bbcb00a · nodejs/node · GitHub | MISC | github.com | |
| [SECURITY] Fedora 36 Update: rsync-3.2.5-1.fc36 - package-announce - Fedora Mailing-Lists | MISC | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: zlib-1.2.11-33.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| oss-security - Re: zlib buffer overflow | MLIST | www.openwall.com | |
| [SECURITY] Fedora 37 Update: zlib-1.2.12-5.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-5218-1 zlib | DEBIAN | www.debian.org | |
| About the security content of watchOS 9.1 - Apple Support | CONFIRM | support.apple.com | |
| About the security content of iOS 15.7.1 and iPadOS 15.7.1 - Apple Support | CONFIRM | support.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160175 Oracle Enterprise Linux Security Update for zlib (ELSA-2022-7106)
- 160195 Oracle Enterprise Linux Security Update for zlib (ELSA-2022-7314)
- 160204 Oracle Enterprise Linux Security Update for zlib (ELSA-2022-9987)
- 160205 Oracle Enterprise Linux Security Update for zlib (ELSA-2022-9988)
- 160252 Oracle Enterprise Linux Security Update for rsync security and enhancement update (ELSA-2022-7793)
- 160264 Oracle Enterprise Linux Security Update for rsync (ELSA-2022-8291)
- 160496 Oracle Enterprise Linux Security Update for zlib (ELSA-2023-1095)
- 180965 Debian Security Update for zlib (DSA 5218-1)
- 181046 Debian Security Update for zlib (DLA 3103-1)
- 184903 Debian Security Update for zliblibz-mingw-w64 (CVE-2022-37434)
- 198903 Ubuntu Security Notification for zlib Vulnerability (USN-5570-1)
- 198905 Ubuntu Security Notification for rsync Vulnerability (USN-5573-1)
- 198991 Ubuntu Security Notification for zlib Vulnerability (USN-5570-2)
- 20344 Oracle MySQL April 2023 Critical Patch Update (CPUAPR2023)
- 20389 IBM DB2 Multiple Vulnerabilities (7087162)
- 240779 Red Hat Update for zlib (RHSA-2022:7106)
- 240809 Red Hat Update for zlib (RHSA-2022:7314)
- 240827 Red Hat Update for rsync (RHSA-2022:7793)
- 240908 Red Hat Update for rsync (RHSA-2022:8291)
- 241242 Red Hat Update for zlib (RHSA-2023:1095)
- 242697 Red Hat Update for rsync (RHSA-2024:0254)
- 257227 CentOS Security Update for zlib (CESA-2023:1095)
- 283050 Fedora Security Update for rsync (FEDORA-2022-25e4dbedf9)
- 283075 Fedora Security Update for rsync (FEDORA-2022-15da0cf165)
- 283082 Fedora Security Update for zlib (FEDORA-2022-b8232d1cca)
- 283123 Fedora Security Update for zlib (FEDORA-2022-0b517a5397)
- 296084 Oracle Solaris 11.4 Support Repository Update (SRU) 50.126.3 Missing (CPUOCT2022)
- 330143 IBM AIX Denial of Service (DoS) due to zlib and zlibNX (zlib_advisory2)
- 354068 Amazon Linux Security Advisory for zlib : ALAS2-2022-1849
- 354259 Amazon Linux Security Advisory for zlib : ALAS-2022-1650
- 354390 Amazon Linux Security Advisory for rsync : ALAS2022-2022-158
- 354392 Amazon Linux Security Advisory for zlib : ALAS2022-2022-252
- 354438 Amazon Linux Security Advisory for rsync : ALAS2022-2022-148
- 354551 Amazon Linux Security Advisory for zlib : ALAS-2022-252
- 355132 Amazon Linux Security Advisory for zlib : ALAS2023-2023-003
- 355190 Amazon Linux Security Advisory for rsync : ALAS2023-2023-002
- 355384 Amazon Linux Security Advisory for rsync : ALAS2-2023-2074
- 377897 Alibaba Cloud Linux Security Update for rsync security and enhancement update (moderate) (ALINUX3-SA-2023:0005)
- 377909 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJAN2023)
- 378117 Alibaba Cloud Linux Security Update for zlib (ALINUX2-SA-2023:0015)
- 378433 Oracle Hypertext Transfer Protocol Server (HTTP Server) Server Multiple Vulnerabilities (CPUAPR2023)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 502475 Alpine Linux Security Update for zlib
- 502976 Alpine Linux Security Update for zlib-ng
- 503674 Alpine Linux Security Update for zlib
- 505843 Alpine Linux Security Update for zlib-ng
- 505979 Alpine Linux Security Update for zlib
- 591311 Bosch Rexroth PRA-ES8P2S Ethernet-Switch Multiple Vulnerabilities (BOSCH-SA-247053-BT)
- 610440 Apple iOS 15.7.1 and iPadOS 15.7.1 Security Update Missing
- 610441 Apple iOS 16.1 and iPadOS 16 Security Update Missing
- 6140119 AWS Bottlerocket Security Update for libz (GHSA-w5mr-8397-m99w)
- 672199 EulerOS Security Update for zlib (EulerOS-SA-2022-2485)
- 672222 EulerOS Security Update for zlib (EulerOS-SA-2022-2641)
- 672259 EulerOS Security Update for sudo (EulerOS-SA-2022-2701)
- 672276 EulerOS Security Update for mariadb-connector-c (EulerOS-SA-2022-2691)
- 672283 EulerOS Security Update for mariadb-connector-c (EulerOS-SA-2022-2659)
- 672293 EulerOS Security Update for zlib (EulerOS-SA-2022-2673)
- 672299 EulerOS Security Update for rsync (EulerOS-SA-2022-2664)
- 672301 EulerOS Security Update for sudo (EulerOS-SA-2022-2669)
- 672303 EulerOS Security Update for zlib (EulerOS-SA-2022-2705)
- 672316 EulerOS Security Update for rsync (EulerOS-SA-2022-2696)
- 672317 EulerOS Security Update for zlib (EulerOS-SA-2022-2715)
- 672339 EulerOS Security Update for mariadb-connector-c (EulerOS-SA-2022-2771)
- 672359 EulerOS Security Update for zlib (EulerOS-SA-2022-2787)
- 672360 EulerOS Security Update for zlib (EulerOS-SA-2022-2752)
- 672372 EulerOS Security Update for rsync (EulerOS-SA-2022-2777)
- 672376 EulerOS Security Update for deltarpm (EulerOS-SA-2022-2723)
- 672379 EulerOS Security Update for deltarpm (EulerOS-SA-2022-2758)
- 672381 EulerOS Security Update for mariadb-connector-c (EulerOS-SA-2022-2736)
- 672394 EulerOS Security Update for rsync (EulerOS-SA-2022-2742)
- 672438 EulerOS Security Update for deltarpm (EulerOS-SA-2022-2841)
- 672469 EulerOS Security Update for deltarpm (EulerOS-SA-2022-2816)
- 672530 EulerOS Security Update for binutils (EulerOS-SA-2023-1094)
- 672548 EulerOS Security Update for binutils (EulerOS-SA-2023-1118)
- 672666 EulerOS Security Update for binutils (EulerOS-SA-2023-1349)
- 672667 EulerOS Security Update for binutils (EulerOS-SA-2023-1377)
- 672681 EulerOS Security Update for binutils (EulerOS-SA-2023-1420)
- 672685 EulerOS Security Update for binutils (EulerOS-SA-2023-1405)
- 690930 Free Berkeley Software Distribution (FreeBSD) Security Update for Free Berkeley Software Distribution (FreeBSD) (a1323a76-28f1-11ed-a72a-002590c1f29c)
- 691150 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (f504a8d2-e105-11ed-85f6-84a93843eb75)
- 710671 Gentoo Linux zlib Multiple Vulnerabilities (GLSA 202210-42)
- 752485 SUSE Enterprise Linux Security Update for zlib (SUSE-SU-2022:2847-1)
- 752487 SUSE Enterprise Linux Security Update for zlib (SUSE-SU-2022:2846-1)
- 752523 SUSE Enterprise Linux Security Update for zlib (SUSE-SU-2022:2947-1)
- 902669 Common Base Linux Mariner (CBL-Mariner) Security Update for zlib (10473)
- 902672 Common Base Linux Mariner (CBL-Mariner) Security Update for zlib (10470)
- 903714 Common Base Linux Mariner (CBL-Mariner) Security Update for zlib (10473-1)
- 903898 Common Base Linux Mariner (CBL-Mariner) Security Update for zlib (10470-1)
- 904813 Common Base Linux Mariner (CBL-Mariner) Security Update for python2 (12413)
- 904832 Common Base Linux Mariner (CBL-Mariner) Security Update for tcl (12451)
- 904840 Common Base Linux Mariner (CBL-Mariner) Security Update for cloud-hypervisor (12304)
- 904869 Common Base Linux Mariner (CBL-Mariner) Security Update for boost (12301)
- 904872 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (12305)
- 904880 Common Base Linux Mariner (CBL-Mariner) Security Update for gdb (12333)
- 904888 Common Base Linux Mariner (CBL-Mariner) Security Update for mariadb (12362)
- 904889 Common Base Linux Mariner (CBL-Mariner) Security Update for grpc (12344)
- 904899 Common Base Linux Mariner (CBL-Mariner) Security Update for mozjs60 (12370)
- 904902 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (12442)
- 904911 Common Base Linux Mariner (CBL-Mariner) Security Update for binutils (12299)
- 904912 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (12415)
- 904914 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (12382)
- 904915 Common Base Linux Mariner (CBL-Mariner) Security Update for nmap (12394)
- 904943 Common Base Linux Mariner (CBL-Mariner) Security Update for erlang (12323)
- 904946 Common Base Linux Mariner (CBL-Mariner) Security Update for openjdk8 (12405)
- 904952 Common Base Linux Mariner (CBL-Mariner) Security Update for ccache (12302)
- 904959 Common Base Linux Mariner (CBL-Mariner) Security Update for gcc (12332)
- 904971 Common Base Linux Mariner (CBL-Mariner) Security Update for syslinux (12445)
- 904972 Common Base Linux Mariner (CBL-Mariner) Security Update for nss (12396)
- 904979 Common Base Linux Mariner (CBL-Mariner) Security Update for erlang (12483)
- 904983 Common Base Linux Mariner (CBL-Mariner) Security Update for binutils (12461)
- 904987 Common Base Linux Mariner (CBL-Mariner) Security Update for cloud-hypervisor (12464)
- 904996 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (12612)
- 904998 Common Base Linux Mariner (CBL-Mariner) Security Update for nss (12599)
- 905027 Common Base Linux Mariner (CBL-Mariner) Security Update for syslinux (12655)
- 905029 Common Base Linux Mariner (CBL-Mariner) Security Update for mariadb-connector-c (12564)
- 905032 Common Base Linux Mariner (CBL-Mariner) Security Update for nmap (12595)
- 905034 Common Base Linux Mariner (CBL-Mariner) Security Update for tcl (12656)
- 905044 Common Base Linux Mariner (CBL-Mariner) Security Update for grpc (12492)
- 905059 Common Base Linux Mariner (CBL-Mariner) Security Update for boost (12462)
- 905081 Common Base Linux Mariner (CBL-Mariner) Security Update for cmake (12473)
- 905094 Common Base Linux Mariner (CBL-Mariner) Security Update for gdb (12487)
- 905097 Common Base Linux Mariner (CBL-Mariner) Security Update for mariadb (12562)
- 905101 Common Base Linux Mariner (CBL-Mariner) Security Update for crash (12481)
- 905104 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (12633)
- 905129 Common Base Linux Mariner (CBL-Mariner) Security Update for rubygem-mini_portile2 (12632)
- 905132 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (12571)
- 905152 Common Base Linux Mariner (CBL-Mariner) Security Update for gcc (12486)
- 940715 AlmaLinux Security Update for zlib (ALSA-2022:7106)
- 940724 AlmaLinux Security Update for zlib (ALSA-2022:7314)
- 940733 AlmaLinux Security Update for rsync (ALSA-2022:7793)
- 940803 AlmaLinux Security Update for rsync (ALSA-2022:8291)
- 960237 Rocky Linux Security Update for zlib (RLSA-2022:7106)
- 960550 Rocky Linux Security Update for rsync (RLSA-2022:8291)
- 960554 Rocky Linux Security Update for zlib (RLSA-2022:7314)
- 960606 Rocky Linux Security Update for rsync (RLSA-2022:7793)