Heap-based buffer overflow in Zlib - CVE-2022-42800
Published: October 27, 2022 / Updated: October 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing gzip files. A remote attacker can pass a specially crafted file to the affected application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
macOS
Apple iOS
iPadOS
watchOS
How to mitigate CVE-2022-42800
macOS - addressed in versions 11.7.1 20G918, 12.6.1 21G217, 13.0 22A380
Apple iOS - addressed in versions 15.7.1 19H117, 16.1 20B82
iPadOS - addressed in versions 15.7.1 19H117, 16.1 20B82
watchOS - update to 9.1 20S75
External References
Related Security Bulletins
- Remote code execution in zlib
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple macOS Monterey