Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow.
A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software.
Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
References
Link | Resource |
---|---|
https://github.com/cloudflare/zlib | Product |
https://github.com/cloudflare/zlib/security/advisories/GHSA-vww9-j87r-4cqh | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cloudflare
Published: 2024-01-04T11:11:07.558Z
Updated: 2024-01-04T11:14:15.933Z
Reserved: 2023-12-20T10:48:40.396Z
Link: CVE-2023-6992
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-04T12:15:23.690
Modified: 2024-01-10T01:14:35.027
Link: CVE-2023-6992
JSON object: View
Redhat Information
No data.