zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
{
"binaries": [
{
"binary_version": "1:1.2.11.dfsg-0ubuntu2.2",
"binary_name": "lib32z1"
},
{
"binary_version": "1:1.2.11.dfsg-0ubuntu2.2",
"binary_name": "lib64z1"
},
{
"binary_version": "1:1.2.11.dfsg-0ubuntu2.2",
"binary_name": "libx32z1"
},
{
"binary_version": "1:1.2.11.dfsg-0ubuntu2.2",
"binary_name": "zlib1g"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1:1.2.11.dfsg-2ubuntu1.5",
"binary_name": "lib32z1"
},
{
"binary_version": "1:1.2.11.dfsg-2ubuntu1.5",
"binary_name": "lib64z1"
},
{
"binary_version": "1:1.2.11.dfsg-2ubuntu1.5",
"binary_name": "libx32z1"
},
{
"binary_version": "1:1.2.11.dfsg-2ubuntu1.5",
"binary_name": "zlib1g"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1:1.2.11.dfsg-2ubuntu9.2",
"binary_name": "lib32z1"
},
{
"binary_version": "1:1.2.11.dfsg-2ubuntu9.2",
"binary_name": "lib64z1"
},
{
"binary_version": "1:1.2.11.dfsg-2ubuntu9.2",
"binary_name": "libx32z1"
},
{
"binary_version": "1:1.2.11.dfsg-2ubuntu9.2",
"binary_name": "zlib1g"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1:1.2.8.dfsg-1ubuntu1.1+esm2",
"binary_name": "lib32z1"
},
{
"binary_version": "1:1.2.8.dfsg-1ubuntu1.1+esm2",
"binary_name": "lib64z1"
},
{
"binary_version": "1:1.2.8.dfsg-1ubuntu1.1+esm2",
"binary_name": "libx32z1"
},
{
"binary_version": "1:1.2.8.dfsg-1ubuntu1.1+esm2",
"binary_name": "zlib-bin"
},
{
"binary_version": "1:1.2.8.dfsg-1ubuntu1.1+esm2",
"binary_name": "zlib1g"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_version": "1:1.2.8.dfsg-2ubuntu4.3+esm2",
"binary_name": "lib32z1"
},
{
"binary_version": "1:1.2.8.dfsg-2ubuntu4.3+esm2",
"binary_name": "lib64z1"
},
{
"binary_version": "1:1.2.8.dfsg-2ubuntu4.3+esm2",
"binary_name": "libx32z1"
},
{
"binary_version": "1:1.2.8.dfsg-2ubuntu4.3+esm2",
"binary_name": "zlib1g"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}