Summary
A critical vulnerability (CVSS Score 9.8) is reported in the latest version (1.2.12) of a popular component - zlib (https://github.com/madler/zlib). This article discusses the impact, if any, on InstallShield.
Description
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
NOTE: Only applications that call inflateGetHeader are affected. Upon analysis, neither InstallShield nor other third party components used in InstallShield are calling this method, hence it is not impacted by the vulnerability.
Resolution
No fix is required.
Workaround
No workaround is required.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37434
Related Articles
CVE-2023-45853: Zlib Vulnerability mpact on InstallShield 10Number of Views INDEX: Log4j vulnerability impact on FlexNet Publisher 6Number of Views Suite Project Build Error -7239 3Number of Views Vulnerability: CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher 20Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago