[CLSA-2022:1649170583] Fix CVE(s): CVE-2018-25032
Type:
security
Severity:
moderate
Release date:
2022-04-05 14:56:23 UTC
Description:
* SECURITY UPDATE: memory corruption when deflating - debian/patches/CVE-2018-25032-1.patch: fix a bug that can crash deflate on some input when using Z_FIXED in deflate.c, deflate.h. - debian/patches/CVE-2018-25032-2.patch: assure that the number of bits for deflatePrime() is valid in deflate.c. - CVE-2018-25032
Updated packages:
  • lib32z1_1.2.8.dfsg-2ubuntu4.3+tuxcare.els1_amd64.deb
    sha:14671ce7fb4a9d6b13d047169de60855f5dadf55
  • lib32z1-dev_1.2.8.dfsg-2ubuntu4.3+tuxcare.els1_amd64.deb
    sha:03b2e26f35d5c65c34b8413ef5ec118c6e50780d
  • libx32z1_1.2.8.dfsg-2ubuntu4.3+tuxcare.els1_amd64.deb
    sha:dc4387a7569195bf6645ebdc737ffbd6556efeb5
  • libx32z1-dev_1.2.8.dfsg-2ubuntu4.3+tuxcare.els1_amd64.deb
    sha:b1ca2a2176b0e7bf8fd10942d7db2eb684a40b66
  • zlib1g_1.2.8.dfsg-2ubuntu4.3+tuxcare.els1_amd64.deb
    sha:c3b4bf9369adc99ba684e13f8dabddb94835b66a
  • zlib1g-dev_1.2.8.dfsg-2ubuntu4.3+tuxcare.els1_amd64.deb
    sha:50b68f8cb4599255da3d3a7bc7cdb34ba71f7168
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.