CVE-2022-37434

Siemens ProductCERT Advisory SSA-398330

criticalEPSS 18%

Description

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Metrics

Severity
critical
no public PoC known
9.8
Source: nvd-v3
97.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
17.8 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2022-03-15 17:05 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux9.0

  • linux

    ubuntu / linuxbionic

  • linux

    ubuntu / linux-awsbionic

  • linux

    ubuntu / linux-aws-fipsbionic

  • linux

    ubuntu / linux-azure-4.15bionic

  • linux

    ubuntu / linux-azure-fipsbionic

  • linux

    ubuntu / linux-fipsbionic

  • linux

    ubuntu / linux-gcp-4.15bionic

  • linux

    ubuntu / linux-gcp-fipsbionic

  • linux

    ubuntu / linux-kvmbionic

  • linux

    linux / linux_kernel6.10

  • linux

    linux / linux_kernel6.11

  • linux

    linux / linux_kernel6.12

  • linux

    linux / linux_kernel6.13

  • linux

    linux / linux_kernel6.9

  • linux

    linux / linux_kernel

  • linux

    ubuntu / opensslbionic

  • linux

    ubuntu / opensslfocal

  • linux

    ubuntu / openssltrusty

  • linux

    ubuntu / opensslxenial

  • linux

    ubuntu / openssl1.0bionic

  • macos

    apple / mac_os_x10.15.7

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • azul

    zulu

  • bitnami

    node-min12.0.0

  • bitnami

    node-min12.13.0

  • bitnami

    node-min14.0.0

  • bitnami

    node-min14.15.0

  • bitnami

    node-min16.0.0

  • bitnami

    node-min16.13.0

  • bitnami

    node-min17.0.0

  • Dell

    NetWorkerVirtual Edition

  • Dell

    NetWorkervProxy

  • Dell

    PowerProtect Data Domain7.10.1.70

  • Dell

    PowerProtect Data Domain7.13.1.40

  • Dell

    PowerProtect Data Domain8.3.1.10

  • Dell

    PowerProtect Data Domain8.4.0.0

  • Dell

    PowerProtect Data Domain< 7.10.1.70

    fixed in 7.10.1.70

  • Dell

    PowerProtect Data Domain< 7.13.1.40

    fixed in 7.13.1.40

  • Dell

    PowerProtect Data Domain< 8.3.1.10

    fixed in 8.3.1.10

  • Dell

    PowerProtect Data Domain< 8.4.0.0

    fixed in 8.4.0.0

  • goto

    gotoassist11.9.18

  • HPE

    HP-UXOpenSSL Software <A.03.00.15.001

  • IBM

    AIX7.2

  • IBM

    AIX7.3

References & sources

Linked CVEs

Show 37 more CVEs
IDCVE-2022-37434