Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software. Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: cloudflare

Published: 2024-01-04T11:11:07.558Z

Updated: 2024-01-04T11:14:15.933Z

Reserved: 2023-12-20T10:48:40.396Z


Link: CVE-2023-6992

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-04T12:15:23.690

Modified: 2024-01-10T01:14:35.027


Link: CVE-2023-6992

JSON object: View

cve-icon Redhat Information

No data.