AVG-2821 log

Package zlib
Status Fixed
Severity High
Type arbitrary code execution
Affected 1:1.2.12-2
Fixed 1:1.2.12-3
Current 1:1.3.1-2 [core]
Ticket None
Created Thu Jan 26 19:41:28 2023
Issue Severity Remote Type Description
CVE-2022-37434 High No Arbitrary code execution
A security vulnerability was found in zlib. The flaw triggered a heap- based buffer in inflate in the inflate.c function via a large gzip header extra...
References
https://web.archive.org/web/20221108034231/https://github.com/ivd38/zlib_overflow
https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d