VDB
RHSA-2002%3A027
RHSA-2002%3A027
PUBLISHED
CVSS 7 HIGH
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.
Risk Scores
CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Powertools 7.0 | |
| Red Hat | Red Hat Powertools 6.2 | |
| Red Hat | Red Hat Powertools 7.1 |
Timeline
- Mar 11, 2002 CVE Published
- Aug 4, 2026 CVE Updated
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2002:027 advisory
- http://bugzilla.gnome.org/show_bug.cgi?id=70594 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2002/rhsa-2002_027.json advisory
- https://access.redhat.com/security/cve/CVE-2002-0059 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616731 issue
- https://www.cve.org/CVERecord?id=CVE-2002-0059 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-0059 advisory