This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
- Revenera Community
- :
- InstallShield
- :
- InstallShield Knowledge Base
- :
- CVE-2022-37434: zlib vulnerability impact on InstallShield
Subscribe
- Mark as New
- Mark as Read
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
CVE-2022-37434: zlib vulnerability impact on InstallShield
CVE-2022-37434: zlib vulnerability impact on InstallShield
Summary:
A critical vulnerability (CVSS Score 9.8) is reported in the latest version (1.2.12) of a popular component - zlib (https://github.com/madler/zlib). This article discusses the impact, if any, on InstallShield.
Description:
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Upon analysis, neither InstallShield nor other third party components used in InstallShield are calling this method, hence it is not impacted by the vulnerability.
Resolution:
No fix is required.
Workaround:
No workaround is required.
References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37434
No ratings
Comments
Sep 17, 2022
01:05 AM
- Mark as Read
- Mark as New
- Permalink
- Report Inappropriate Content
Sep 17, 2022
01:05 AM
What about InstallAnywhere?