CVE-2018-25032
High · CVSS 7.5zlib / nokogiri (RubyGems) — Out-of-bounds Write / Memory Corruption during deflate compression (CWE-787)
- CVSS
- 7.5
- nvd
- EPSS
- 52.1%
- 99th pct
- KEV
- No
- Class
- oss containerizable
- CWE-787, CWE-787
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Search profile — drives PoC discovery
Symbols deflatezlibdeflateInitdeflateInit2compresscompress2deflateEndZ_DEFLATEDdistant matchesmatch_headstrstartlookahead
Keywords CVE-2018-25032zlib memory corruptionzlib deflate distant matcheszlib before 1.2.12nokogiri zlib CVE-2018-25032zlib out-of-bounds writezlib compression vulnerabilityzlib deflate exploitCWE-787 zlib
Versions: zlib < 1.2.12; nokogiri (all versions bundling zlib < 1.2.12)
Ranked PoCs (14) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0
- ★ 1Trinadh465/external_zlib_4.4_CVE-2018-25032 needs reviewgh_search · C
- ★ 0ChrisAdkin8/Nomad-Job-Vulnerability-Tagging needs reviewtrickest
- ★ 0NathanielAPawluk/sec-buddy needs reviewtrickest
- ★ 0Satheesh575555/external_zlib-1.2.7_CVE-2018-25032 needs reviewgh_search · C
- ★ 0Trinadh465/external_zlib_AOSP10_r33_CVE-2018-25032 needs reviewgh_search · C
- ★ 0Webb-L/reptileIndexOfProject needs reviewtrickest
- ★ 0ZipArchive/ZipArchive needs reviewtrickest
- ★ 0gatecheckdev/gatecheck needs reviewtrickest
- ★ 0isgo-golgo13/gokit-gorillakit-enginesvc needs reviewtrickest
- ★ 0mario206/UnityReleaseNotes-latest needs reviewtrickest
- ★ 0yeforriak/snyk-to-cve needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| RubyGems | nokogiri | 0 → 1.13.4 |
References
- http://seclists.org/fulldisclosure/2022/May/33
- http://seclists.org/fulldisclosure/2022/May/35
- http://seclists.org/fulldisclosure/2022/May/38
- http://www.openwall.com/lists/oss-security/2022/03/25/2
- http://www.openwall.com/lists/oss-security/2022/03/26/1
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
- https://github.com/madler/zlib/issues/605
- https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
- https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z