ALAS2-2023-2074

Related Vulnerabilities: CVE-2022-37434  

A security vulnerability was found in zlib. The flaw triggered a heap-based buffer in inflate in the inflate.c function via a large gzip header extra field. This flaw is only applicable in the call inflateGetHeader. (CVE-2022-37434)

ALAS2-2023-2074


Amazon Linux 2 Security Advisory: ALAS-2023-2074
Advisory Release Date: 2023-06-05 16:39 Pacific
Advisory Updated Date: 2023-06-07 22:38 Pacific
Severity: Medium

Issue Overview:

A security vulnerability was found in zlib. The flaw triggered a heap-based buffer in inflate in the inflate.c function via a large gzip header extra field. This flaw is only applicable in the call inflateGetHeader. (CVE-2022-37434)


Affected Packages:

rsync


Issue Correction:
Run yum update rsync to update your system.

New Packages:
aarch64:
    rsync-3.1.2-11.amzn2.0.2.aarch64
    rsync-debuginfo-3.1.2-11.amzn2.0.2.aarch64

i686:
    rsync-3.1.2-11.amzn2.0.2.i686
    rsync-debuginfo-3.1.2-11.amzn2.0.2.i686

src:
    rsync-3.1.2-11.amzn2.0.2.src

x86_64:
    rsync-3.1.2-11.amzn2.0.2.x86_64
    rsync-debuginfo-3.1.2-11.amzn2.0.2.x86_64