This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
- Revenera Community
- :
- InstallShield
- :
- InstallShield Knowledge Base
- :
- CVE-2022-37434: zlib vulnerability impact on InstallShield
Subscribe
- Mark as New
- Mark as Read
- Subscribe
- Printer Friendly Page
CVE-2022-37434: zlib vulnerability impact on InstallShield
CVE-2022-37434: zlib vulnerability impact on InstallShield
Summary:
A critical vulnerability (CVSS Score 9.8) is reported in the latest version (1.2.12) of a popular component - zlib (https://github.com/madler/zlib). This article discusses the impact, if any, on InstallShield.
Description:
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Upon analysis, neither InstallShield nor other third party components used in InstallShield are calling this method, hence it is not impacted by the vulnerability.
Resolution:
No fix is required.
Workaround:
No workaround is required.
References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37434
No ratings