CVE-2023-37187: Null Pointer Dereference
Published Dec 25, 2023
·Updated
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfpaccdecompress. function.
Affected Software
1 affected component
blosc C-Blosc2<2.9.3
Remediation
Event History
Dec 25, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37187?
CVE-2023-37187 has been classified with a severity level that indicates a potential denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2023-37187?
To remediate CVE-2023-37187, upgrade C-blosc2 to version 2.9.3 or later.
3
What software is affected by CVE-2023-37187?
CVE-2023-37187 affects C-blosc2 versions prior to 2.9.3.
4
What effect does CVE-2023-37187 have on systems?
CVE-2023-37187 can lead to application crashes or denial of service due to improper handling of NULL pointers.
5
When was CVE-2023-37187 discovered?
CVE-2023-37187 was discovered prior to the release of version 2.9.3 of C-blosc2.