logo

Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz

ID: 7374c669-3087-5097-848b-19f938ec8abb

STIX ID: report--7374c669-3087-5097-848b-19f938ec8abb

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-01-12

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** A global buffer overflow vulnerability in the zlib untgz utility v1.3.1.2 stems from an unbounded strcpy() in TGZfname() that copies command-line archive names into a fixed 1,024-byte global buffer, enabling denial-of-service, memory corruption, and potentially arbitrary code execution; researchers demonstrated the issue with AddressSanitizer showing a 2,001-byte out-of-bounds write when invoked with a 4,096-byte filename, and no CVE has yet been assigned.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.