CVE-2022-37434

CRITICAL

Zlib < 1.2.12 - Out-of-Bounds Write

Title source: rule

Description

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Exploits (3)

nomisec WORKING POC 3 stars
by xen0bit · poc
https://github.com/xen0bit/CVE-2022-37434_poc
nomisec STUB
by Trinadh465 · poc
https://github.com/Trinadh465/external_zlib_CVE-2022-37434

References (27)

... and 7 more

Scores

CVSS v3 9.8
EPSS 0.9254
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120 CWE-787
Status published
Products (20)
apple/ipados < 15.7.1
apple/iphone_os < 15.7.1
apple/macos 11.0 - 11.7.1
apple/watchos < 9.1
debian/debian_linux 10.0
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
netapp/active_iq_unified_manager (2 CPE variants)
netapp/h300s_firmware
... and 10 more
Published Aug 05, 2022
Tracked Since Feb 18, 2026