MidnightBSD

Advisories for zlib

CVE-2002-0059 HIGH

The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-415,

Products Affected

Vendor Product Version
zlib zlib *
CVE-2003-0107 HIGH

Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
zlib zlib 1.1.4
CVE-2004-0797 LOW

The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
zlib zlib 1.2.1
CVE-2005-1849 MEDIUM

inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
zlib zlib 1.2.2
CVE-2005-2096 HIGH

zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
zlib zlib 1.2.1
zlib zlib 1.2.0
zlib zlib 1.2.2
CVE-2013-0296 MEDIUM

Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
zlib pigz *
CVE-2015-1191 MEDIUM

Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
zlib pigz 2.3.1
CVE-2016-9840 MEDIUM

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oracle mysql *
oracle database_server 18c
oracle jre 1.6.0
oracle jdk 1.7.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 7.5
oracle jdk 1.6.0
redhat enterprise_linux_server 6.0
oracle jre 1.8.0
redhat enterprise_linux_workstation 6.0
apple watchos *
apple mac_os_x *
oracle jdk 1.8.0
opensuse opensuse 13.2
canonical ubuntu_linux 18.04
boost boost *
redhat enterprise_linux_server 7.0
zlib zlib *
canonical ubuntu_linux 16.04
nodejs node.js *
opensuse leap 42.1
redhat satellite 5.8
apple iphone_os *
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_workstation 7.0
opensuse leap 42.2
debian debian_linux 8.0
oracle jre 1.7.0
redhat enterprise_linux_eus 7.4
apple tvos *
CVE-2016-9841 HIGH

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
netapp hci_storage_node -
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 7.5
oracle jdk 1.6.0
netapp symantec_netbackup -
redhat enterprise_linux_server 6.0
redhat enterprise_linux_workstation 6.0
netapp e-series_santricity_management -
netapp e-series_santricity_storage_manager -
netapp e-series_santricity_web_services -
oracle jdk 1.8.0
opensuse opensuse 13.2
canonical ubuntu_linux 18.04
redhat enterprise_linux_server 7.0
netapp oncommand_shift -
nodejs node.js *
netapp active_iq_unified_manager *
redhat satellite 5.8
apple iphone_os *
redhat enterprise_linux_workstation 7.0
debian debian_linux 8.0
oracle jre 1.7.0
netapp virtual_storage_console -
netapp oncommand_balance -
netapp oncommand_insight -
netapp oncommand_unified_manager -
oracle mysql *
oracle database_server 18c
netapp cloud_backup -
oracle jre 1.6.0
oracle jdk 1.7.0
netapp vasa_provider_for_clustered_data_ontap *
oracle jre 1.8.0
netapp steelstore_cloud_integrated_storage -
apple watchos *
netapp solidfire -
apple mac_os_x *
netapp oncommand_unified_manager *
netapp oncommand_workflow_automation -
zlib zlib *
canonical ubuntu_linux 16.04
netapp snapmanager -
opensuse leap 42.1
redhat enterprise_linux_desktop 7.0
netapp oncommand_performance_manager -
opensuse leap 42.2
netapp storage_replication_adapter_for_clustered_data_ontap -
redhat enterprise_linux_eus 7.4
netapp e-series_santricity_os_controller *
apple tvos *
CVE-2016-9843 HIGH

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
netapp oncommand_insight -
oracle mysql *
oracle database_server 18c
oracle jre 1.6.0
oracle jdk 1.7.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 7.5
oracle jdk 1.6.0
mariadb mariadb *
redhat enterprise_linux_server 6.0
oracle jre 1.8.0
redhat enterprise_linux_workstation 6.0
apple watchos *
apple mac_os_x *
netapp snapcenter -
oracle jdk 1.8.0
opensuse opensuse 13.2
canonical ubuntu_linux 18.04
redhat enterprise_linux_server 7.0
netapp oncommand_workflow_automation -
zlib zlib *
canonical ubuntu_linux 16.04
nodejs node.js *
opensuse leap 42.1
netapp active_iq_unified_manager *
redhat satellite 5.8
apple iphone_os *
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_workstation 7.0
opensuse leap 42.2
debian debian_linux 8.0
oracle jre 1.7.0
redhat enterprise_linux_eus 7.4
apple tvos *
CVE-2018-25032 MEDIUM

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,CWE-787,

Products Affected

Vendor Product Version
azul zulu 7.52
fedoraproject fedora 35
azul zulu 15.38
netapp h410s_firmware -
apple mac_os_x 10.15.7
fedoraproject fedora 36
netapp h500s_firmware -
azul zulu 6.45
mariadb mariadb *
netapp h300s_firmware -
netapp h700s_firmware -
siemens scalance_sc626-2c_firmware *
debian debian_linux 11.0
debian debian_linux 9.0
azul zulu 11.54
siemens scalance_sc636-2c_firmware *
apple mac_os_x *
goto gotoassist *
netapp active_iq_unified_manager -
siemens scalance_sc622-2c_firmware *
fedoraproject fedora 34
siemens scalance_sc646-2c_firmware *
python python *
netapp oncommand_workflow_automation -
zlib zlib *
apple macos *
azul zulu 13.46
netapp h410c_firmware -
azul zulu 8.60
netapp management_services_for_element_software -
siemens scalance_sc632-2c_firmware *
debian debian_linux 10.0
netapp hci_compute_node -
nokogiri nokogiri *
netapp e-series_santricity_os_controller *
netapp ontap_select_deploy_administration_utility -
azul zulu 17.32
siemens scalance_sc642-2c_firmware *
CVE-2022-37434

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Products Affected

Vendor Product Version
netapp hci -
netapp active_iq_unified_manager -
fedoraproject fedora 35
fedoraproject fedora 37
fedoraproject fedora 36
netapp oncommand_workflow_automation -
zlib zlib *
netapp h500s_firmware -
apple macos *
netapp h300s_firmware -
netapp h700s_firmware -
netapp storagegrid -
netapp management_services_for_element_software -
apple iphone_os *
stormshield stormshield_network_security *
debian debian_linux 10.0
netapp hci_compute_node -
apple watchos *
apple ipados *
netapp ontap_select_deploy_administration_utility -
CVE-2023-45853

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

Products Affected

Vendor Product Version
smihica pyminizip *
zlib zlib *
CVE-2026-22184

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.

Products Affected

Vendor Product Version
zlib zlib *
CVE-2026-27171

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 2.9 LOW CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L 1.4 1.4

Products Affected

Vendor Product Version
zlib zlib *