CVE-2023-6992

Updated: 2024-11-24 04:37:41.203715

Description:

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software. Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU zlib 1.2.11 5.5 MEDIUM Ignored 2024-01-10 08:38:32
CentOS 6 ELS zlib 1.2.3 5.5 MEDIUM Ignored 2024-01-10 08:38:32
CentOS 7 ELS zlib 1.2.7 5.5 MEDIUM Ignored 2024-01-10 08:38:32
CentOS 8.4 ELS zlib 1.2.11-17 5.5 MEDIUM Ignored 2024-01-10 08:38:32
CentOS 8.5 ELS zlib 1.2.11-17 5.5 MEDIUM Ignored 2024-01-10 08:38:33
CloudLinux 6 ELS zlib 1.2.3 5.5 MEDIUM Ignored 2024-01-10 08:38:33
Oracle Linux 6 ELS zlib 1.2.3 5.5 MEDIUM Ignored 2024-01-10 08:38:33
Ubuntu 16.04 ELS zlib 1.2.8 5.5 MEDIUM Ignored 2024-01-10 08:38:33
Ubuntu 18.04 ELS zlib 1.2.11 5.5 MEDIUM Released CLSA-2024:1716485905 2024-05-23 14:25:32