zlib is vulnerable to Denial of Service (DoS)
29
Low Risk
crc32_combine64() and crc32_combine_gen64() pass the length into x2nmodp(), whose right shift loop does not stop when that length is negative. A negative length keeps the loop running and consumes CPU without returning. The fix rejects a negative length before entering the loop.
You are affected if you are using a version that falls within the vulnerable range and your application passes a length from untrusted input to crc32_combine64() or crc32_combine_gen64().
zlib is vulnerable to Denial of Service (DoS) in versions 1.2.12 - 1.3.1.
Upgrade the zlib library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.