Vulnerability Change Records for CVE-2023-6992
Change History
New CVE Received from Cloudflare, Inc. 1/04/2024 7:15:23 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Description |
|
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow.
A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software.
Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
|
| Added |
CVSS V3.1 |
|
Cloudflare, Inc. AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
|
| Added |
CWE |
|
Cloudflare, Inc. CWE-122
|
| Added |
CWE |
|
Cloudflare, Inc. CWE-126
|
| Added |
CWE |
|
Cloudflare, Inc. CWE-20
|
| Added |
Reference |
|
Cloudflare, Inc. https://github.com/cloudflare/zlib [No types assigned]
|
| Added |
Reference |
|
Cloudflare, Inc. https://github.com/cloudflare/zlib/security/advisories/GHSA-vww9-j87r-4cqh [No types assigned]
|
|