Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8: 2022-0124 Critical Advisory for zlib Memory Corruption

mageia
Calendar Grey March 31, 2022
Dist Mageia Esm H88
New zlib updates for Mageia address memory corruption vulnerabilities linked to CVE-2018-25032. Additional information on security protocols included.
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches

Summary

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. (CVE-2018-25032) Update to release 1.2.12 for additional bug fixes. See the changelog for details.

References

- https://bugs.mageia.org/show_bug.cgi?id=30204

- https://www.openwall.com/lists/oss-security/2022/03/24/1

- https://www.openwall.com/lists/oss-security/2022/03/25/2

- https://www.zlib.net/ChangeLog.txt

- https://www.cve.org/CVERecord?id=CVE-2018-25032

Resolution

SRPMS

- 8/core/zlib-1.2.12-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 31 Mar 2022
URL: https://advisories.mageia.org/MGASA-2022-0124.html
Type: security
CVE: CVE-2018-25032

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here