zlib through 1.2.12 has a heap-based buffer over-read or...
Critical severity
Unreviewed
Published
Aug 6, 2022
to the GitHub Advisory Database
•
Updated May 6, 2023
Description
Published by the National Vulnerability Database
Aug 5, 2022
Published to the GitHub Advisory Database
Aug 6, 2022
Last updated
May 6, 2023
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
References