zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"173736815835493425863590097173702475962",
"129220127786011023031116653503455261516",
"158253382744967794372166426227829451328",
"208646129568712116042670616434092925745",
"267897132422978847766130599021982102399",
"89021460256006972424927287623588351745",
"257784892650917064621950304120855216852"
]
},
"source": "https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1",
"deprecated": false,
"id": "CVE-2022-37434-9cc3d83a",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "inflate.c"
}
}
]