U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-6992

Change History

New CVE Received from Cloudflare, Inc. 1/04/2024 7:15:23 AM

Action Type Old Value New Value
Added Description

								
							
							
						
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow.
A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software.
Patches: The issue has been patched in commit  8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
Added CVSS V3.1

								
							
							
						
Cloudflare, Inc. AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Added CWE

								
							
							
						
Cloudflare, Inc. CWE-122
Added CWE

								
							
							
						
Cloudflare, Inc. CWE-126
Added CWE

								
							
							
						
Cloudflare, Inc. CWE-20
Added Reference

								
							
							
						
Cloudflare, Inc. https://github.com/cloudflare/zlib [No types assigned]
Added Reference

								
							
							
						
Cloudflare, Inc. https://github.com/cloudflare/zlib/security/advisories/GHSA-vww9-j87r-4cqh [No types assigned]