CVE-2023-37185: Null Pointer Dereference
Published Dec 25, 2023
·Updated
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfpprecdecompress at zfp/blosc2-zfp.c.
Affected Software
1 affected component
blosc C-Blosc2<2.9.3
Remediation
Event History
Dec 25, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37185?
CVE-2023-37185 has a medium severity due to the potential for a denial of service caused by a NULL pointer dereference.
2
How do I fix CVE-2023-37185?
To fix CVE-2023-37185, upgrade C-blosc2 to version 2.9.3 or later.
3
What is the nature of the vulnerability in CVE-2023-37185?
CVE-2023-37185 is a NULL pointer dereference vulnerability that occurs in the zfp_prec_decompress function.
4
Which versions of C-blosc2 are affected by CVE-2023-37185?
CVE-2023-37185 affects all versions of C-blosc2 before 2.9.3.
5
Can CVE-2023-37185 lead to remote exploits?
CVE-2023-37185 does not directly lead to remote exploits but can cause a denial of service if exploited.