Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Whether to trigger the zlib vulnerability #709

Open
beibeiGeng opened this issue Jun 3, 2024 · 1 comment
Open

Whether to trigger the zlib vulnerability #709

beibeiGeng opened this issue Jun 3, 2024 · 1 comment

Comments

@beibeiGeng
Copy link

Does the zipArchive software actively trigger the zilb vulnerability?

@Coeur
Copy link
Member

Coeur commented Jun 3, 2024

So the topic is: https://nvd.nist.gov/vuln/detail/cve-2018-25032
Link says that old vulnerability (published 2 years ago) affects system zlib in:

  • macOS From (including) 10.15 Up to (excluding) 10.15.7
  • macOS From (including) 11.0 Up to (excluding) 11.6.6
  • macOS From (including) 12.0.0 Up to (excluding) 12.4

The vulnerability only happens when uncompressing malicious archives on those systems.

So:

  • If you're compressing and uncompressing only your own-made archives (not user-provided ones), you may be fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants