7.5
CVSSv2

CVE-2002-0059

Published: 15/03/2002 Updated: 02/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The decompression algorithm in zlib 1.1.3 and previous versions, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote malicious users to execute arbitrary code via a block of malformed compression data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zlib zlib

Vendor Advisories

The compression library zlib has a flaw in which it attempts to free memory more than once under certain conditions This can possibly be exploited to run arbitrary code in a program that includes zlib If a network application running as root is linked to zlib, this could potentially lead to a remote root compromise No exploits are known at this ...
There is a vulnerability in the zlib compression library This code is used in multiple applications While we have not identified any Cisco product that is directly impacted by the vulnerability, there are several products that are using third-party modules that are vulnerable or that are running on an operating system that is vulnerable ...