Search CVE reports
1 – 10 of 12 results
CVE-2023-45853
Medium priorityMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE:...
3 affected packages
klibc, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Not affected | Not affected | Not affected | Not affected | Not affected |
rsync | Not affected | Not affected | Not affected | Not affected | Not affected |
zlib | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2022-37434
Medium priorityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle...
3 affected packages
klibc, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Fixed | Fixed | Fixed | Fixed | Fixed |
rsync | Not affected | Not affected | Fixed | Fixed | Fixed |
zlib | Not affected | Fixed | Fixed | Fixed | Fixed |
CVE-2018-25032
Medium priorityzlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
5 affected packages
klibc, mariadb-10.3, mariadb-10.6, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Fixed | Fixed | Fixed | Fixed | Fixed |
mariadb-10.3 | — | Not in release | Fixed | Not in release | Ignored |
mariadb-10.6 | Not in release | Fixed | Not in release | Not in release | Ignored |
rsync | Not affected | Not affected | Fixed | Fixed | Fixed |
zlib | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2021-31873
Low prioritySome fixes available 4 of 6
An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow.
1 affected packages
klibc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-31872
Low prioritySome fixes available 4 of 6
An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact.
1 affected packages
klibc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-31871
Low prioritySome fixes available 4 of 6
An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.
1 affected packages
klibc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-31870
Low prioritySome fixes available 4 of 6
An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow.
1 affected packages
klibc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | — | Not affected | Fixed | Fixed | Fixed |
CVE-2011-1930
Low priorityIn klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with...
1 affected packages
klibc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | — | — | — | — | — |
CVE-2016-9843
Low prioritySome fixes available 15 of 21
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
3 affected packages
klibc, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
zlib | Not affected | Not affected | Not affected | Not affected | Fixed |
CVE-2016-9842
Low prioritySome fixes available 15 of 21
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
3 affected packages
klibc, rsync, zlib
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
klibc | Needs evaluation | Not affected | Not affected | Not affected | Not affected |
rsync | Fixed | Fixed | Fixed | Fixed | Fixed |
zlib | Not affected | Not affected | Not affected | Not affected | Fixed |