INFSA-2022:7813: mingw-zlib security update

Information about definition

Identificator: INFSA-2022:7813

Type: security

Release date: 2025-10-31 13:02:51 UTC

Information about package

The zlib packages provide a general-purpose lossless data compression library that is used by many different programs.

Vulnerabilities description

  • CVE-2018-25032

    An out-of-bounds access flaw was found in zlib, which allows memory corruption when deflating (ex: when compressing) if the input has many distant matches. For some rare inputs with a large number of distant matches (crafted payloads), the buffer into which the compressed or deflated data is written can overwrite the distance symbol table which it overlays. This issue results in corrupted output due to invalid distances, which leads to out-of-bound access, corrupting the memory and potentially crashing the application.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.2 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download