Activity log for bug #1994108

Date Who What changed Old value New value Message
2022-10-25 05:22:49 Yue Tao bug added bug
2022-10-25 05:27:36 Yue Tao summary [Debian] CVE-2022-37434: zlib: a heap-based buffer over-read or buffer overflow Debian CVE-2022-37434 / CVE-2018-25032 : zlib: multiple CVEs
2022-10-25 05:27:52 Yue Tao description CVE-2022-37434: [https://nvd.nist.gov/vuln/detail/CVE-2022-37434] zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference). Score: cve_id status cvss3Score av ac pr ui ai CVE-2022-37434 fixed 9.8 N L N N H References: https://security-tracker.debian.org/tracker/DSA-5218-1 ['zlib1g_1:1.2.11.dfsg-2_amd64.deb===>zlib1g_1:1.2.11.dfsg-2+deb11u2_amd64.deb', 'zlib1g-dev_1:1.2.11.dfsg-2_amd64.deb===>zlib1g-dev_1:1.2.11.dfsg-2+deb11u2_amd64.deb'] Found during August 2022 CVE scan using vulscan CVE-2022-37434: [https://nvd.nist.gov/vuln/detail/CVE-2022-37434] zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference). CVE-2018-25032: [https://nvd.nist.gov/vuln/detail/CVE-2018-25032] zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. Score: cve_id status cvss3Score av ac pr ui ai CVE-2022-37434 fixed 9.8 N L N N H CVE-2018-25032 fixed 7.5 N L N N H References: https://security-tracker.debian.org/tracker/DSA-5218-1 ['zlib1g_1:1.2.11.dfsg-2_amd64.deb===>zlib1g_1:1.2.11.dfsg-2+deb11u2_amd64.deb', 'zlib1g-dev_1:1.2.11.dfsg-2_amd64.deb===>zlib1g-dev_1:1.2.11.dfsg-2+deb11u2_amd64.deb'] Found during August 2022 CVE scan using vulscan
2022-10-27 20:57:29 Ghada Khalil starlingx: status New Triaged
2022-10-27 20:57:31 Ghada Khalil starlingx: importance Undecided Medium
2022-10-27 20:57:41 Ghada Khalil tags stx.8.0 stx.security
2022-10-27 20:57:44 Ghada Khalil information type Public Public Security
2022-10-27 20:58:01 Ghada Khalil starlingx: assignee Zhixiong Chi (zhixiongchi)
2022-11-03 01:39:51 Zhixiong Chi cve linked 2018-25032
2022-11-03 01:40:13 Zhixiong Chi cve linked 2022-37434
2022-11-07 06:17:46 Zhixiong Chi starlingx: status Triaged In Progress
2022-11-07 17:10:03 OpenStack Infra starlingx: status In Progress Fix Released