漏洞信息详情
zlib 缓冲区错误漏洞
- CNNVD编号:CNNVD-202208-2276
- 危害等级: 超危
- CVE编号: CVE-2022-37434
- 漏洞类型: 缓冲区错误
- 发布时间: 2022-08-05
- 威胁类型: 远程
- 更新时间: 2022-09-19
- 厂 商:
- 漏洞来源:
漏洞简介
zlib是美国Mark Adler个人开发者的一个通用的数据压缩库。
zlib 1.2.12版本存在安全漏洞,该漏洞源于在 inflate.c 中通过一个大的 gzip 标头额外字段在 inflate 中具有基于堆的缓冲区过度读取或缓冲区溢出。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://github.com/madler/zlib/
参考网址
来源:MISC
链接:https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2022/09/msg00012.HTML
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/
来源:DEBIAN
链接:https://www.debian.org/security/2022/dsa-5218
来源:MISC
链接:https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764
来源:MISC
链接:https://github.com/ivd38/zlib_overflow
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20220901-0005/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2022/08/09/1
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/X5U7OTKZSHY2I3ZFjsR2SHFHW72RKGDK/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2022/08/05/2
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/
来源:MISC
链接:https://github.com/curl/curl/issues/9271
来源:MISC
链接:https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.4108
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/zlib-buffer-overflow-via-inflateGetHeader-39003
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/168113/Ubuntu-Security-Notice-USN-5573-1.HTML
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2022-37434
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/168107/Ubuntu-Security-Notice-USN-5570-1.HTML
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.4133
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.4243
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.4301
来源:cxsecurity.com
链接:https://cxsecurity.com/cveshow/CVE-2022-37434/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.4523
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2022.4139
受影响实体
暂无
补丁
- zlib 缓冲区错误漏洞的修复措施
![weinxin](http://zone.ci/zone_ci_images/zone.ci.png)
评论