CVE-2018-25032

Advisory lineage Upstream: 0 Downstream: 56
Analyzed
Published: 25 Mar 2022, 00:00
Last modified:06 May 2025, 14:19

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.09% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

25 Mar 2022, 00:00
Published
Vulnerability first disclosed
06 May 2025, 14:19
Last Modified
Vulnerability information updated

Description

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.09% Percentile: 25%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • applemac_os_x

    ≥ 10.15, < 10.15.7 | 10.15.7 | 10.15.7:security_update_2020 | 10.15.7:security_update_2020-001 | 10.15.7:security_update_2020-005 | 10.15.7:security_update_2020-007 | 10.15.7:security_update_2021-001 | 10.15.7:security_update_2021-002 | 10.15.7:security_update_2021-003 | 10.15.7:security_update_2021-006 | 10.15.7:security_update_2021-007 | 10.15.7:security_update_2021-008 | 10.15.7:security_update_2022-001 | 10.15.7:security_update_2022-002 | 10.15.7:security_update_2022-003

  • UnknownmacOS

    ≥ 11.0, < 11.6.6 | ≥ 12.0.0, < 12.4

  • azulzulu

    6.45 | 7.52 | 8.60 | 11.54 | 13.46 | 15.38 | 17.32

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    34 | 35 | 36

  • gotogotoassist

    < 11.9.18

  • mariadbmariadb

    ≥ 10.3.0, < 10.3.36 | ≥ 10.4.0, < 10.4.26 | ≥ 10.5.0, < 10.5.17 | ≥ 10.6.0, < 10.6.9 | ≥ 10.7.0, < 10.7.5 | ≥ 10.8.0, < 10.8.4 | ≥ 10.9.0, < 10.9.2

  • netappactive_iq_unified_manager

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.2

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph700s_firmware

    na

  • netapphci_compute_node_firmware

    na

  • netappmanagement_services_for_element_software

    na

  • netapponcommand_workflow_automation

    na

  • netappontap_select_deploy_administration_utility

    na

  • nokogirinokogiri

    < 1.13.4

  • pythonpython

    ≥ 3.7.0, < 3.7.14 | ≥ 3.8.0, < 3.8.14 | ≥ 3.9.0, < 3.9.13 | ≥ 3.10.0, < 3.10.5

  • siemensscalance_sc622-2c_firmware

    < 3.0

  • siemensscalance sc626-2c

    < 3.0

  • siemensscalance_sc632-2c_firmware

    < 3.0

  • siemensscalance_sc636-2c_firmware

    < 3.0

  • siemensscalance_sc642-2c_firmware

    < 3.0

  • siemensscalance_sc646-2c_firmware

    < 3.0

  • zlibzlib

    ≥ 1.2.2.2, < 1.2.12

References (29)