Skip to content

Out-of-bounds Read SNYK-RHEL8-ZLIB-10174471 #4042

@github-actions

Description

@github-actions

NVD Description

Note: Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by RHEL.
See How to fix? for RHEL:8 relevant fixed versions and status.

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic.

Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.

Remediation

There is no fixed version for RHEL:8 zlib.

References

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions