First published: Wed Nov 02 2022(Updated: )
The zlib packages provide a general-purpose lossless data compression library that is used by many different programs.<br>Security Fix(es):<br><li> zlib: a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field (CVE-2022-37434)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/zlib | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/minizip-compat-debuginfo | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/minizip-compat-debuginfo | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-debuginfo | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-debuginfo | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-debugsource | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-debugsource | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-devel | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-devel | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/minizip-compat-debuginfo | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-debuginfo | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-debugsource | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-devel | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/minizip-compat-debuginfo | <1.2.11-32.el9_0.aa | 1.2.11-32.el9_0.aa |
redhat/zlib | <1.2.11-32.el9_0.aa | 1.2.11-32.el9_0.aa |
redhat/zlib-debuginfo | <1.2.11-32.el9_0.aa | 1.2.11-32.el9_0.aa |
redhat/zlib-debugsource | <1.2.11-32.el9_0.aa | 1.2.11-32.el9_0.aa |
redhat/zlib-devel | <1.2.11-32.el9_0.aa | 1.2.11-32.el9_0.aa |
redhat/zlib-static | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-static | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-static | <1.2.11-32.el9_0 | 1.2.11-32.el9_0 |
redhat/zlib-static | <1.2.11-32.el9_0.aa | 1.2.11-32.el9_0.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:7314 is categorized as important due to a heap-based buffer over-read or overflow vulnerability.
To fix RHSA-2022:7314, update the affected zlib packages to version 1.2.11-32.el9_0 or later.
The affected packages include zlib, minizip-compat-debuginfo, zlib-debuginfo, zlib-devel, zlib-debugsource, and zlib-static.
CVE-2022-37434 refers to the specific vulnerability that allows a heap-based buffer over-read or overflow within the zlib library.
There are no specific workarounds mentioned for RHSA-2022:7314, making it essential to apply the provided patches.