imPC@ndo IT

Tracker / CVE-2018-25032

CVE-2018-25032

High 7.5

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Affected products and versions

apple mac_os_x
apple mac_os_x · 10.15 → 10.15.7
apple macos · 11.0 → 11.6.6
apple macos · 12.0.0 → 12.4
azul zulu
debian debian_linux
fedoraproject fedora
goto gotoassist · … → 11.9.18
mariadb mariadb · 10.3.0 → 10.3.36
mariadb mariadb · 10.4.0 → 10.4.26
mariadb mariadb · 10.5.0 → 10.5.17
mariadb mariadb · 10.6.0 → 10.6.9
mariadb mariadb · 10.7.0 → 10.7.5
mariadb mariadb · 10.8.0 → 10.8.4
mariadb mariadb · 10.9.0 → 10.9.2
netapp active_iq_unified_manager
netapp e-series_santricity_os_controller · 11.0.0 → 11.70.2
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500s_firmware
netapp h700s_firmware
netapp hci_compute_node
netapp management_services_for_element_software
netapp oncommand_workflow_automation
netapp ontap_select_deploy_administration_utility
nokogiri nokogiri · … → 1.13.4
python python · 3.10.0 → 3.10.5
python python · 3.7.0 → 3.7.14
python python · 3.8.0 → 3.8.14
python python · 3.9.0 → 3.9.13
siemens scalance_sc622-2c_firmware · … → 3.0
siemens scalance_sc626-2c_firmware · … → 3.0
siemens scalance_sc632-2c_firmware · … → 3.0
siemens scalance_sc636-2c_firmware · … → 3.0
siemens scalance_sc642-2c_firmware · … → 3.0
siemens scalance_sc646-2c_firmware · … → 3.0
zlib zlib · 1.2.2.2 → 1.2.12

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References