VDB

RHSA-2002%3A027

RHSA-2002%3A027 PUBLISHED CVSS 7 HIGH

The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Powertools 7.0
Red HatRed Hat Powertools 6.2
Red HatRed Hat Powertools 7.1

Timeline

  • Mar 11, 2002 CVE Published
  • Aug 4, 2026 CVE Updated
  • Aug 7, 2026 Distribution Patch
  • Aug 7, 2026 Distribution Patch
  • Aug 7, 2026 Security Advisory
  • Aug 7, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›