peter bassill · operator
$ cve CVE-2022-37434 JSON

CVE-2022-37434

9.8
CRITICAL · CVSS 3.1 · EPSS 19% (pctl 97)

Patch early

EPSS 19% — above the 10% action threshold.

Description

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS18.97% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2022-08-05
Last modified2026-07-14

Affected (21)

VendorProduct
appleipados
appleiphone os
applemacos
applewatchos
debiandebian linux
fedoraprojectfedora
netappactive iq unified manager
netapph300s
netapph300s firmware
netapph500s
netapph500s firmware
netapph700s
netapph700s firmware
netapphci
netapphci compute node
netappmanagement services for element software
netapponcommand workflow automation
netappontap select deploy administration utility
netappstoragegrid
stormshieldstormshield network security
zlibzlib

References

→ the Explorer  ·  watch your stack  ·  NVD