RHSA-2022:4845: Important: zlib security update
The zlib packages provide a general-purpose lossless data compression library that is used by many different programs.Security Fix(es): zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/zlibto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4 - Upgrade
Upgrade
redhat/zlib-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4 - Upgrade
Upgrade
redhat/zlib-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4 - Upgrade
Upgrade
redhat/zlib-develto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4 - Upgrade
Upgrade
redhat/zlibto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4.aa - Upgrade
Upgrade
redhat/zlib-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4.aa - Upgrade
Upgrade
redhat/zlib-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4.aa - Upgrade
Upgrade
redhat/zlib-develto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4.aa - Upgrade
Upgrade
redhat/zlib-staticto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4 - Upgrade
Upgrade
redhat/zlib-staticto a version that resolves this vulnerability.Fixed in 1.2.11-18.el8_4.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4845?
The severity of RHSA-2022:4845 is classified as moderate due to a flaw in zlib when compressing certain inputs.
How do I fix RHSA-2022:4845?
To fix RHSA-2022:4845, upgrade to zlib version 1.2.11-18.el8_4 or a newer version.
What software packages are affected by RHSA-2022:4845?
The affected software packages include zlib, zlib-debuginfo, zlib-devel, zlib-debugsource, and zlib-static.
Is RHSA-2022:4845 related to CVE-2018-25032?
Yes, RHSA-2022:4845 addresses the flaw found in zlib related to CVE-2018-25032.
What platforms are impacted by RHSA-2022:4845?
RHSA-2022:4845 impacts several platforms including x86_64 and ppc64le versions of Red Hat.