Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow.
A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software.
Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cloudflare
Published: 2024-01-04T11:11:07.558Z
Updated: 2024-09-06T18:16:58.376Z
Reserved: 2023-12-20T10:48:40.396Z
Link: CVE-2023-6992
Vulnrichment
Updated: 2024-08-02T08:50:07.582Z
NVD
Status : Modified
Published: 2024-01-04T12:15:23.690
Modified: 2024-11-21T08:44:59.467
Link: CVE-2023-6992
Redhat
No data.