Buffer overflow in Zlib - CVE-2018-25032
Published: March 28, 2022 / Updated: December 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when compressing data. A remote attacker can pass specially crafted input to the application, trigger memory corruption and perform a denial of service (DoS) attack.
Affected software
MongoDB driver for C
VMware Tanzu Application Service for VMs
Isolation Segment
App Connect Enterprise Certified Container
IBM Operations Analytics Predictive Insights
Service Telemetry Framework
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
IBM Security Guardium Key Lifecycle Manager (GKLM)
Red Hat Advanced Cluster Security for Kubernetes
Oracle VM Server for x86
IBM Cloud Object Storage Systems
Dell Secure Connect Gateway
IBM Intelligent Operations Center
OpenShift Logging
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
WebSphere Remote Server
Oracle Communications Diameter Signaling Router
Tenable Nessus
IBM Security Verify Governance
Oracle HTTP Server
IBM Robotic Process Automation
Oracle Communications Cloud Native Core Network Exposure Function
Autodesk Infraworks
Spectrum Discover
IBM Aspera Orchestrator
Session Smart Router
IBM Tivoli Business Service Manager
IBM Tivoli Monitoring
PowerProtect Data Domain
IBM MQ
IBM QRadar WinCollect Agent
IBM Spectrum Protect Plus
Red Hat OpenStack
NetWorker
SPSS Statistics
Arch Linux
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Anolis OS
IBM AIX
IBM i
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Linux
macOS
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
Oracle Solaris
FreeBSD
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
openSUSE Leap
openEuler
Fedora
Edgecross Basic Software for Developers ECP-BS1-W-D
Edgecross Basic Software for Windows ECP-BS1-W
IBM Security Verify Gateway
cflinuxfs3
Tanzu Greenplum for Kubernetes
IBM Watson Machine Learning Accelerator
RecoverPoint Classic
Db2 Big SQL
IBM OpenPages with Watson
Content Manager OnDemand for Multiplatforms
dashDB Local
Oracle Siebel CRM
Autodesk AutoCAD
IBM Aspera Shares
IBM Aspera Console
EMC ECS
IBM Sterling Connect:Direct for i5/OS
Platform Automation Toolkit
Database Operator for FoundationDB
Cognos Dashboards on Cloud Pak for Data
XtremIO X2
Storage Protect Server
IBM Engineering Systems Design Rhapsody
Wyse Device Agent
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SINAMICS GL150
LANTIME Operating System Firmware (LTOS)
SCALANCE S615
API Manager
Red Hat OpenShift GitOps
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
IBM QRadar Network Packet Capture
IBM QRadar Network Security
IBM Integrated Analytics System
API Gateway
IBM VIOS
elfutils (Red Hat package)
zlib (Red Hat package)
imgbased (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
redhat-virtualization-host-productimg (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
klibc-utils (Ubuntu package)
libklibc (Ubuntu package)
zlib-debugsource
zlib-debuginfo
zlib-32bit
zlib
zlib-static
zlib-devel
minizip-devel
minizip
lib64z1 (Ubuntu package)
libx32z1 (Ubuntu package)
lib32z1 (Ubuntu package)
zlib1g (Ubuntu package)
mingw64-zlib-static
mingw64-zlib
mingw32-zlib-static
mingw32-zlib
mingw-zlib (Red Hat package)
libz1-debuginfo-32bit
libz1-debuginfo
libz1-32bit
libz1
zlib (Debian package)
zlib-devel-static
zlib-devel-32bit
zlib-help
libz1-32bit-debuginfo
libminizip1-debuginfo
libminizip1
sys-libs/zlib
rsync
rsync (Ubuntu package)
rsync (Red Hat package)
rsync-daemon
libpython3_9-1_0-32bit
python39-testsuite-debuginfo
libpython3_9-1_0-32bit-debuginfo
python39-32bit
python39-32bit-debuginfo
python39-base-32bit
python39-base-32bit-debuginfo
python39-base-debuginfo
python39-tk
python39-tools
python39-tk-debuginfo
python39-base
python39-idle
libpython3_9-1_0-debuginfo
python39-debuginfo
python39-debugsource
python39-testsuite
python39-devel
python39-dbm-debuginfo
python39-dbm
python39-curses-debuginfo
python39-curses
python39-core-debugsource
python39-doc
python39-doc-devhelp
libpython3_9-1_0
python39
ovirt-node-ng (Red Hat package)
mariadb-server (Ubuntu package)
libmariadbd19-debuginfo
mariadb-client-debuginfo
mariadb-errormessages
mariadb-tools-debuginfo
mariadb-tools
mariadb-debugsource
mariadb-debuginfo
mariadb-client
mariadb
libmariadbd19
libmariadbd-devel
uboot-tools
Red Hat OpenShift Serverless
Harbor
OpenShift Service Mesh
VMware Tanzu Operations Manager
Red Hat Virtualization
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Spectrum Virtualize
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
IBM Tivoli Network Manager (ITNM)
IBM Connect Direct for Microsoft Windows
IBM Edge Application Manager
IBM DataPower Gateway
IBM Spectrum Protect Backup-Archive Client
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Oracle Outside In Technology
Discourse
Red Hat Virtualization Host
MySQL Server
Oracle Database Server
IBM DB2
Splunk Universal Forwarder
Oracle Communications Session Border Controller
IBM Security Verify Access
Juniper Junos Space
Zimbra Collaboration
PeopleSoft Enterprise PeopleTools
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Unified Data Repository
IBM Spectrum Protect for Space Management
AutoCAD Electrical
AutoCAD Architecture
AutoCAD Mac LT
AutoCAD Mac
AutoCAD LT
Autodesk Civil 3D
AutoCAD Map 3D
AutoCAD Plant 3D
AutoCAD Mechanical
AutoCAD MEP
AutoCAD for Mac LT
Advance Steel
Alias Surface
Alias AutoStudio
Alias Concept
SCALANCE WAM766-1 (EU)
SCALANCE WAM766-1 (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 EEC (US)
SCALANCE WUM763-1
SCALANCE WUM766-1 (EU)
SCALANCE WUM766-1 (US)
SCALANCE WAM763-1
SCALANCE SC646-2C
SCALANCE SC642-2C
SCALANCE SC626-2C
SCALANCE SC622-2C
SCALANCE SC632-2C
SCALANCE SC636-2C
SCALANCE M876-4 (NAM)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
RUGGEDCOM RM1224 LTE(4G) EU
IBM Cloud Pak System
ownCloud Android App
Dell EMC Storage Monitoring and Reporting (SMR)
Kaspersky Security for Virtual Environments Light Agent for Windows (eng)
Kaspersky Security for Virtual Environments Light Agent for Windows (fr)
Kaspersky Security for Virtual Environments Light Agent for Windows (de)
Kaspersky Security for Virtual Environments Light Agent for Linux
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
Spectrum Protect Server
How to mitigate CVE-2018-25032
VMware Tanzu Application Service for VMs - addressed in versions 2.7.49, 2.10.31, 2.11.19, 2.12.12, 2.13.4
Isolation Segment - addressed in versions 2.7.44, 2.10.24, 2.11.13, 2.12.7
API Manager - addressed in versions August 2022, May 2022
API Gateway - addressed in versions August 2022, May 2022
cflinuxfs3 - addressed in versions 0.280.0, 0.281.0
elfutils (Red Hat package) - update to 0.186-1.el8
Red Hat OpenShift Serverless - addressed in versions 1, 1.22.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.0.1
MongoDB driver for C - update to 1.21.2
App Connect Enterprise Certified Container - addressed in versions 1.1.10, 4.2.0
zlib (Red Hat package) - addressed in versions 1.2.3-31.el6_10, 1.2.7-17.el7_4.1, 1.2.7-18.el7_6.1, 1.2.7-18.el7_7.1, 1.2.7-20.el7_9, 1.2.11-17.el8_2, 1.2.11-18.el8_4, 1.2.11-18.el8_5, 1.2.11-31.el9_0.1
imgbased (Red Hat package) - update to 1.2.24-1.el8ev
Red Hat OpenShift GitOps - update to 1.5
Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.2, 1.7.3, 1.7.4
Harbor - update to 1.10.11
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Cryostat - addressed in versions 2.1.0, 2.1.1
Discourse - addressed in versions 2.8.3, 2.9.0 beta4
OpenShift Service Mesh - update to 2.1.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.10, 2.3.11, 2.4.4, 2.4.5
VMware Tanzu Operations Manager - addressed in versions 2.9.41, 2.10.44
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70
Red Hat OpenShift Container Platform - addressed in versions 3.11.705, 4.6.58, 4.7.51, 4.8.41, 4.9.35, 4.11.0
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.15
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.23-1.el7ev, 4.5.0-5.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.3.23-20220622.0.el7_9
redhat-virtualization-host-productimg (Red Hat package) - addressed in versions 4.3.23-1.el7, 4.5.0-2.el8
IBM Aspera Faspex for Linux - update to 4.4.2 PL2
IBM Aspera Faspex for Windows - update to 4.4.2 PL2
OpenShift Virtualization - addressed in versions 4.8.7, 4.10.2, 4.11.0
IBM Connect Direct for Microsoft Windows - addressed in versions 4.8.0.3_iFix044, 6.0.0.4_iFix051, 6.1.0.2_iFix042, 6.2.0.3_iFix004
Dell Secure Connect Gateway - update to 5.12.00.10
RecoverPoint Classic - update to 5.1 SP4 P4
OpenShift Logging - addressed in versions 5.2.10, 5.3.7, 5.4.1
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.031, 7.04.016
Db2 Big SQL - update to 7.6.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Zimbra Collaboration - addressed in versions 8.8.15 Patch 37, 9.0.0 Patch 30
Tenable Nessus - update to 10.2.0
IBM Security Verify Access - update to 10.0.5.0
Content Manager OnDemand for Multiplatforms - update to 10.5.0.5
IBM DataPower Gateway - addressed in versions 10.5.0.17, 10.6.0.5, 10.6.4.0
macOS - addressed in versions 10.15.7 19H1922, 11.6.6 20G624, 12.4 21F79
dashDB Local - update to 11.5.9.0
IBM Robotic Process Automation - update to 21.0.2.5
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Autodesk AutoCAD - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Electrical - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Architecture - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Mac LT - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Mac - addressed in versions 2022.1.3, 2023.1.1
AutoCAD LT - addressed in versions 2022.1.3, 2023.1.1
Autodesk Civil 3D - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Map 3D - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Plant 3D - addressed in versions 2022.1.3, 2023.1.1
AutoCAD Mechanical - addressed in versions 2022.1.3, 2023.1.1
AutoCAD MEP - addressed in versions 2022.1.3, 2023.1.1
AutoCAD for Mac LT - addressed in versions 2022.1.3, 2023.1.1
Advance Steel - addressed in versions 2022.1.3, 2023.1.1
Alias Surface - update to 2023.0.1
Alias AutoStudio - update to 2023.0.1
Alias Concept - update to 2023.0.1
klibc-utils (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.7-1ubuntu5.2, 2.0.10-4ubuntu0.1, 2.0.13-1ubuntu0.1, 2.0.13-4ubuntu0.1
libklibc (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.7-1ubuntu5.2, 2.0.10-4ubuntu0.1, 2.0.13-1ubuntu0.1, 2.0.13-4ubuntu0.1
zlib-debugsource - addressed in versions 1.2.7-0.17.3.1, 1.2.8-12.6.1, 1.2.11-3.6.1, 1.2.11-11.19.1, 1.2.11-150000.3.30.1
zlib-debuginfo - update to 1.2.7-0.17.3.1
zlib-32bit - update to 1.2.7-0.17.3.1
zlib - update to 1.2.7-0.17.3.1
zlib-static - update to 1.2.7-20
zlib-devel - addressed in versions 1.2.7-20, 1.2.11-18.0.1
zlib - addressed in versions 1.2.7-20, 1.2.11-18.0.1
minizip-devel - update to 1.2.7-20
minizip - update to 1.2.7-20
lib64z1 (Ubuntu package) - addressed in versions 1:1.2.8.dfsg2ubuntu4.3+esm1, 1:1.2.11.dfsg-2ubuntu1.3, 1:1.2.11.dfsg-0ubuntu2.1, 1:1.2.11.dfsg-2ubuntu7.1
libx32z1 (Ubuntu package) - addressed in versions 1:1.2.8.dfsg2ubuntu4.3+esm1, 1:1.2.11.dfsg-2ubuntu1.3, 1:1.2.11.dfsg-0ubuntu2.1, 1:1.2.11.dfsg-2ubuntu7.1
lib32z1 (Ubuntu package) - addressed in versions 1:1.2.8.dfsg2ubuntu4.3+esm1, 1:1.2.11.dfsg-2ubuntu1.3, 1:1.2.11.dfsg-0ubuntu2.1, 1:1.2.11.dfsg-2ubuntu7.1
zlib1g (Ubuntu package) - addressed in versions 1:1.2.8.dfsg2ubuntu4.3+esm1, 1:1.2.11.dfsg-2ubuntu1.3, 1:1.2.11.dfsg-0ubuntu2.1, 1:1.2.11.dfsg-2ubuntu7.1
zlib - update to 1.2.8-7.20
mingw64-zlib-static - update to 1.2.8-10
mingw64-zlib - update to 1.2.8-10
mingw32-zlib-static - update to 1.2.8-10
mingw32-zlib - update to 1.2.8-10
mingw-zlib (Red Hat package) - addressed in versions 1.2.8-10.el8, 1.2.12-2.el9
zlib-devel - addressed in versions 1.2.8-12.6.1, 1.2.11-3.6.1, 1.2.11-11.19.1, 1.2.11-150000.3.30.1
libz1-debuginfo-32bit - addressed in versions 1.2.8-12.6.1, 1.2.11-3.6.1, 1.2.11-11.19.1
libz1-debuginfo - addressed in versions 1.2.8-12.6.1, 1.2.11-3.6.1, 1.2.11-11.19.1, 1.2.11-150000.3.30.1
libz1-32bit - addressed in versions 1.2.8-12.6.1, 1.2.11-3.6.1, 1.2.11-11.19.1, 1.2.11-150000.3.30.1
libz1 - addressed in versions 1.2.8-12.6.1, 1.2.11-3.6.1, 1.2.11-11.19.1, 1.2.11-150000.3.30.1
zlib (Debian package) - addressed in versions 1:1.2.11.dfsg-1+deb10u1, 1:1.2.11.dfsg-2+deb11u1
zlib-devel-static - addressed in versions 1.2.11-11.19.1, 1.2.11-150000.3.30.1
zlib-devel-32bit - addressed in versions 1.2.11-11.19.1, 1.2.11-150000.3.30.1
zlib - update to 1.2.11-18
zlib-help - update to 1.2.11-18
zlib-devel - update to 1.2.11-18
zlib-debugsource - update to 1.2.11-18
zlib-debuginfo - update to 1.2.11-18
minizip - update to 1.2.11-18
minizip-devel - update to 1.2.11-18
zlib - addressed in versions 1.2.11-31.fc35, 1.2.11-32.fc36
libz1-32bit-debuginfo - update to 1.2.11-150000.3.30.1
minizip-devel - update to 1.2.11-150000.3.30.1
libminizip1-debuginfo - update to 1.2.11-150000.3.30.1
libminizip1 - update to 1.2.11-150000.3.30.1
sys-libs/zlib - update to 1.2.12-r3
IBM Aspera Shares - update to 1.10.0 PL4
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
SCALANCE WAM763-1 - update to 2.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
ownCloud Android App - update to 2.10.1
SCALANCE SC646-2C - update to 3.0
SCALANCE SC642-2C - update to 3.0
SCALANCE SC626-2C - update to 3.0
SCALANCE SC622-2C - update to 3.0
SCALANCE SC632-2C - update to 3.0
SCALANCE SC636-2C - update to 3.0
rsync - update to 3.0.6-12.14
rsync (Ubuntu package) - addressed in versions 3.1.2-2.1ubuntu1.4, 3.1.3-8ubuntu0.3, 3.1.13ubuntu1.3+esm1
rsync (Red Hat package) - addressed in versions 3.1.3-6.el8_1.1, 3.1.3-7.el8_2.1, 3.1.3-12.el8_4.1, 3.1.3-14.el8_6.2, 3.2.3-9.el9_0.1
rsync-daemon - update to 3.1.3-14
rsync - update to 3.1.3-14
rsync - addressed in versions 3.2.3-6.fc34, 3.2.3-9.fc35, 3.2.3-15.fc36
IBM Aspera Console - update to 3.4.5
EMC ECS - update to 3.7.0.2
IBM Sterling Connect:Direct for i5/OS - update to 3.8.0.3
libpython3_9-1_0-32bit - update to 3.9.13-150300.4.13.1
python39-testsuite-debuginfo - update to 3.9.13-150300.4.13.1
libpython3_9-1_0-32bit-debuginfo - update to 3.9.13-150300.4.13.1
python39-32bit - update to 3.9.13-150300.4.13.1
python39-32bit-debuginfo - update to 3.9.13-150300.4.13.1
python39-base-32bit - update to 3.9.13-150300.4.13.1
python39-base-32bit-debuginfo - update to 3.9.13-150300.4.13.1
python39-base-debuginfo - update to 3.9.13-150300.4.13.1
python39-tk - update to 3.9.13-150300.4.13.1
python39-tools - update to 3.9.13-150300.4.13.1
python39-tk-debuginfo - update to 3.9.13-150300.4.13.1
python39-base - update to 3.9.13-150300.4.13.1
python39-idle - update to 3.9.13-150300.4.13.1
libpython3_9-1_0-debuginfo - update to 3.9.13-150300.4.13.1
python39-debuginfo - update to 3.9.13-150300.4.13.1
python39-debugsource - update to 3.9.13-150300.4.13.1
python39-testsuite - update to 3.9.13-150300.4.13.1
python39-devel - update to 3.9.13-150300.4.13.1
python39-dbm-debuginfo - update to 3.9.13-150300.4.13.1
python39-dbm - update to 3.9.13-150300.4.13.1
python39-curses-debuginfo - update to 3.9.13-150300.4.13.1
python39-curses - update to 3.9.13-150300.4.13.1
python39-core-debugsource - update to 3.9.13-150300.4.13.1
python39-doc - update to 3.9.13-150300.4.13.1
python39-doc-devhelp - update to 3.9.13-150300.4.13.1
libpython3_9-1_0 - update to 3.9.13-150300.4.13.1
python39 - update to 3.9.13-150300.4.13.1
IBM Aspera Orchestrator - update to 4.0.1.2b9681
ovirt-node-ng (Red Hat package) - update to 4.4.2-1.el8ev
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
Database Operator for FoundationDB - update to 4.6.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
Cognos Dashboards on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Kaspersky Security for Virtual Environments Light Agent for Windows (eng) - update to 5.2 pf225
Kaspersky Security for Virtual Environments Light Agent for Windows (fr) - update to 5.2 pf226
Kaspersky Security for Virtual Environments Light Agent for Windows (de) - update to 5.2 pf227
Kaspersky Security for Virtual Environments Light Agent for Linux - update to 5.2.27-1843
IBM QRadar Network Security - addressed in versions 5.4.0.17, 5.5.0.12
Session Smart Router - addressed in versions 5.4.7, 5.5.3
IBM Tivoli Business Service Manager - update to 6.2.0.5.4
IBM Tivoli Monitoring - update to 6.3.0.7 Service pack 13
XtremIO X2 - update to 6.4.1-11
SCALANCE S615 - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
PowerProtect Data Domain - addressed in versions 7.7.4, 7.10.0.0
IBM Spectrum Virtualize - addressed in versions 7.8.1.16, 8.2.1.16, 8.3.1.8, 8.4.0.7, 8.5.0.5, 8.5.2.0
IBM Integrated Analytics System - update to 7.9.22.10.SP14
IBM MQ - addressed in versions 8.0.0.16, 9.0.0.13, 9.1.0.11, 9.2.0.6, 9.3
IBM Spectrum Protect for Space Management - update to 8.1.17.0
Spectrum Protect Server - update to 8.1.17
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.0
IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - update to 8.1.17.0
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.17.0
Storage Protect Server - update to 8.1.22
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM QRadar WinCollect Agent - update to 10.1.1
IBM Spectrum Protect Plus - update to 10.1.12
mariadb-server (Ubuntu package) - addressed in versions 1:10.3.37-0ubuntu0.20.04.1, 1:10.6.11-0ubuntu0.22.04.1, 1:10.6.11-0ubuntu0.22.10.1
libmariadbd19-debuginfo - update to 10.4.26-150200.3.31.1
mariadb-client-debuginfo - update to 10.4.26-150200.3.31.1
mariadb-errormessages - update to 10.4.26-150200.3.31.1
mariadb-tools-debuginfo - update to 10.4.26-150200.3.31.1
mariadb-tools - update to 10.4.26-150200.3.31.1
mariadb-debugsource - update to 10.4.26-150200.3.31.1
mariadb-debuginfo - update to 10.4.26-150200.3.31.1
mariadb-client - update to 10.4.26-150200.3.31.1
mariadb - update to 10.4.26-150200.3.31.1
libmariadbd19 - update to 10.4.26-150200.3.31.1
libmariadbd-devel - update to 10.4.26-150200.3.31.1
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7, 11.5, 11.5.9
mariadb - update to 10.5.17
Wyse Device Agent - update to 14.6.8
Red Hat OpenStack - update to 16.2
NetWorker - update to 19.9.0.1
Juniper Junos Space - update to 22.2R1
SPSS Statistics - update to 29.0.1.0
uboot-tools - update to 2022.04-2.fc36
External References
Related Security Bulletins
- Memory corruption in zlib
- Slackware Linux update for zlib
- Ubuntu update for zlib
- Ubuntu update for zlib
- Denial of service in cflinuxfs3
- Debian update for zlib
- Arch Linux update for zlib
- Ubuntu update for rsync
- Multiple vulnerabilities in FreeBSD
- Buffer overflow in IBM Cloud Object Storage Systems
- Red Hat Enterprise Linux 8 update for zlib
- Red Hat Enterprise Linux 8.2 update for zlib
- Red Hat Enterprise Linux 8.2 update for rsync
- Red Hat Enterprise Linux Update Services for SAP Solutions 8.1 update for rsync
- Red Hat Enterprise Linux 8.4 update for rsync
- Red Hat Enterprise Linux 8 update for rsync
- Red Hat Enterprise Linux 7 update for zlib
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for zlib
- Multiple vulnerabilities in Red Hat OpenShift Logging
- Multiple vulnerabilities in Harbor
- CentOS 7 update for zlib
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple macOS Catalina
- Multiple vulnerabilities in Cryostat
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Multiple vulnerabilities in OpenShift Container Platform release 4.7
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Multiple vulnerabilities in OpenShift Container Platform 3.11
- Red Hat Enterprise Linux 8.4 Extended Update Support update for zlib
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes
- Multiple vulnerabilities in Red Hat Virtualization 4 for RHEL 8
- Denial of service in mongo-c-driver
- Ubuntu update for rsync
- Multiple vulnerabilities in Cryostat
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.1
- Multiple vulnerabilities in OpenShift Virtualization 4.10
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Buffer overflow in IBM App Connect Enterprise Certified Container
- SUSE update for python39
- Buffer overflow in IBM Sterling Connect:Direct for Microsoft Windows
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Buffer overflow in IBM i
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Buffer overflow in IBM Tivoli Network Manager
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 update for redhat-release-virtualization-host and redhat-virtualization-host
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC)
- Amazon Linux AMI update for zlib
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- VMware Tanzu products update for rsync
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Slackware Linux update for mariadb
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- SUSE update for mariadb
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in Dell Elastic Cloud Storage (ECS)
- IBM AIX and VIOS update for zlib
- IBM Content Manager OnDemand for Multiplatforms update for zlib
- Denial of service in IBM Sterling Connect:Direct for i5/OS
- Denial of service in IBM Cloud Application Performance Managment and IBM Tivoli Composite Application Manager for Transactions
- Denial of service in IBM Tivoli Monitoring Basic Services
- Denial of service in IBM MQ
- Denial of service in Autodesk products
- Multiple Autodesk products update for Zlib
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Oracle Communications Session Border Controller
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Outside In Technology
- Denial of service in IBM Security Verify Gateway/Bridge
- Multiple vulnerabilities in IBM QRadar SIEM
- Gentoo update for zlib
- Red Hat Enterprise Linux 8 update for mingw-zlib
- Red Hat CodeReady Linux Builder 9 update for mingw-zlib
- Ubuntu update for mariadb-10.3
- Amazon Linux AMI update for rsync
- Multiple vulnerabilities in IBM QRadar Wincollect agent
- Multiple vulnerabilities in Siemens SCALANCE SC-600 Family
- Multiple vulnerabilities in IBM QRadar Network Security
- Multiple vulnerabilities in IBM Spectrum Protect Server
- Multiple vulnerabilities in IBM Spectrum Protect for Virtual Environments
- Multiple vulnerabilities in IBM Spectrum Protect for Space Management
- Multiple vulnerabilities in IBM Spectrum Protect Backup-Archive Client
- ownCloud desktop client update for zlib
- IBM Integrated Analytics System update for Zlib
- Multiple vulnerabilities in Dell Technologies PowerProtect DD
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Oracle HTTP Server
- Red Hat Enterprise Linux 9 update for rsync
- Red Hat Enterprise Linux 9 update for zlib
- Buffer overflow in IBM Aspera Orchestrator
- Multiple vulnerabilities in IBM Aspera Faspex
- Multiple vulnerabilities in Zimbra
- Buffer overflow in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
- Red Hat Enterprise Linux 7.4 Advanced Update Support update for zlib
- Red Hat Enterprise Linux 7.6 Advanced Update Support update for zlib
- Red Hat Enterprise Linux 7 update for zlib
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- Multiple vulnerabilities in Siemens SCALANCE W-700 IEEE 802.11ax devices
- SUSE update for zlib
- SUSE update for zlib
- SUSE update for zlib
- SUSE update for zlib
- SUSE update for zlib
- SUSE update for zlib
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in API Gateway and API Manager
- Buffer overflow in IBM SPSS Statistics
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Multiple vulnerabilities in Oracle VM Server for x86
- VMware Tanzu products update for zlib
- VMware Tanzu products update for rsync
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- Multiple vulnerabilities in IBM Spectrum Discover
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Oracle Siebel CRM
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in Dell NetWorker
- Buffer overflow in Dell Wyse Device Agent
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in Edgecross Basic Software for Windows
- Multiple vulnerabilities in IBM Db2
- IBM Cloud Pak System update for Zlib
- openEuler update for zlib
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Ubuntu update for klibc
- Ubuntu update for klibc
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Gentoo update for rsync
- Amazon Linux AMI update for rsync
- Amazon Linux AMI update for zlib
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Aspera Shares
- Multiple vulnerabilities in IBM Aspera Console
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.6
- Fedora 35 update for rsync
- Fedora 36 update for rsync
- Fedora 34 update for rsync
- Fedora 36 update for uboot-tools
- Fedora 36 update for zlib
- Fedora 35 update for zlib
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM dashDB Local
- Anolis OS update for zlib
- Anolis OS update for zlib
- Anolis OS update for rsync
- Anolis OS update for mingw-zlib
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Meinberg LANTIME firmware update for zlib
- Multiple vulnerabilities in IBM DataPower Gateway
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data
- IBM Database Operator for FoundationDB update for Zlib
- Kaspersky Security for Virtual Environments Light Agent update for third-party components
- Multiple vulnerabilities in Discourse