« List of all CVEs

CVE-2002-0059

Published: 6/25/2002 Last updated: 8/8/2024 Reserved: 2/7/2002

The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (13)

bap-std camlzip conf-gd conf-libclang conf-libdw conf-llvm conf-llvm-shared conf-llvm-static conf-mingw-w64-zlib-i686 conf-mingw-w64-zlib-x86_64 conf-taglib conf-zlib kafka

Products affected (1)

Product Vendor Version
n/a n/a < V14.3.0.12

References (32)