-
Notifications
You must be signed in to change notification settings - Fork 2
Description
NVD Description
Note: Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by RHEL.
See How to fix? for RHEL:8 relevant fixed versions and status.
A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic.
Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.
Remediation
There is no fixed version for RHEL:8 zlib.