CVE-2018-25032

Updated: 2026-02-27 03:07:43.051527

Description:

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 8.5 ELS python3 3.6.8 7.5 HIGH Not Vulnerable 2023-10-27 11:18:51 Not affected: CVE-2018-25032 is a flaw in zlib’s deflate implementation, not in minizip itself. Mi...
CentOS 8.5 ELS zlib 1.2.11-17 7.5 HIGH Released CLSA-2022:1652706582 2022-05-05 10:10:53 Not affected: CVE-2018-25032 is a flaw in zlib’s deflate implementation, not in minizip itself. Mi...
CentOS Stream 8 ELS zlib 1.2.11 7.5 HIGH Already Fixed 2025-09-20 03:35:56
CentOS Stream 8 ELS rsync 3.1.3 7.5 HIGH Already Fixed 2025-09-30 05:35:10
CloudLinux 6 ELS zlib 1.2.3 7.5 HIGH Released CLSA-2022:1652706177 2022-05-26 16:03:28
CloudLinux 6 ELS python 2.6.6 7.5 HIGH Not Vulnerable 2022-12-05 19:55:47
CloudLinux 6 ELS rsync 3.0.6 7.5 HIGH Released CLSA-2022:1652986718 2022-05-26 16:03:21
CloudLinux 7 ELS rsync 3.1.2 7.5 HIGH Already Fixed 2025-09-22 20:34:48
CloudLinux 7 ELS zlib 1.2.7 7.5 HIGH Already Fixed 2025-09-20 03:35:55
Oracle Linux 6 ELS zlib 1.2.3 7.5 HIGH Released CLSA-2022:1652706098 2022-05-12 04:16:44
Total: 49