zlib: Double free in inflateEnd
Published Jun 25, 2002
9.8
CRITICALCVSS 3.1
EPSS 9.69%
Description
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.
Affected products
No data.
No data.
Red Hat Linux 6.2
n/a
Fixed · RHSA-2002:026
Red Hat Linux 7.0
n/a
Fixed · RHSA-2002:026
Red Hat Linux 7.1
n/a
Fixed · RHSA-2002:026
Red Hat Linux 7.2
n/a
Fixed · RHSA-2002:026
Red Hat Powertools 6.2
n/a
Fixed · RHSA-2002:027
Red Hat Powertools 7.0
n/a
Fixed · RHSA-2002:027
Red Hat Powertools 7.1
n/a
Fixed · RHSA-2002:027
Red Hat Enterprise Linux 6
zlib
Not affected
Red Hat Enterprise Linux 7
zlib
Not affected
Red Hat Enterprise Linux 8
zlib
Not affected
Red Hat Enterprise Linux 9
zlib
Not affected
Red Hat JBoss Enterprise Application Platform 6
zlib
Not affected
Red Hat Software Collections
rh-nodejs12-nodejs
Not affected
Red Hat Software Collections
rh-nodejs14-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Linux 6.2 | n/a | Fixed | RHSA-2002:026 |
| Red Hat Linux 7.0 | n/a | Fixed | RHSA-2002:026 |
| Red Hat Linux 7.1 | n/a | Fixed | RHSA-2002:026 |
| Red Hat Linux 7.2 | n/a | Fixed | RHSA-2002:026 |
| Red Hat Powertools 6.2 | n/a | Fixed | RHSA-2002:027 |
| Red Hat Powertools 7.0 | n/a | Fixed | RHSA-2002:027 |
| Red Hat Powertools 7.1 | n/a | Fixed | RHSA-2002:027 |
| Red Hat Enterprise Linux 6 | zlib | Not affected | n/a |
| Red Hat Enterprise Linux 7 | zlib | Not affected | n/a |
| Red Hat Enterprise Linux 8 | zlib | Not affected | n/a |
| Red Hat Enterprise Linux 9 | zlib | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | zlib | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs12-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.69% (0.09691) | 95.37th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.51% (0.09511) | 94.80th | v5 (v2026.06.15) |
| Mar 23, 2026 | 28.58% (0.28582) | 96.48th | v4 (v2025.03.14) |
| Feb 3, 2026 | 33.22% (0.33215) | 96.81th | v4 (v2025.03.14) |
| Dec 7, 2025 | 36.55% (0.36552) | 96.95th | v4 (v2025.03.14) |
| Jun 23, 2025 | 34.16% (0.34155) | 96.76th | v4 (v2025.03.14) |
| May 17, 2025 | 35.77% (0.35766) | 96.86th | v4 (v2025.03.14) |
| May 6, 2025 | 32.85% (0.32846) | 96.60th | v4 (v2025.03.14) |
| Mar 30, 2025 | 29.93% (0.29932) | 96.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 36.06% (0.36057) | 95.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 29.93% (0.29932) | 96.25th | v4 (v2025.03.14) |
| Dec 17, 2024 | 63.99% (0.63993) | 98.01th | v3 (v2023.03.01) |
| Feb 8, 2024 | 47.29% (0.47287) | 97.32th | v3 (v2023.03.01) |
| Feb 3, 2024 | 42.04% (0.42041) | 96.99th | v3 (v2023.03.01) |
| Apr 23, 2023 | 41.10% (0.41100) | 96.72th | v3 (v2023.03.01) |
| Mar 7, 2023 | 34.28% (0.34282) | 96.37th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.25% (0.12248) | 95.30th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.25% (0.12248) | 94.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.25% (0.12248) | 89.34th | v2 (v2022.01.01) |
References (20)
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-015.1.txt vendor-advisoryx_refsource_CALDERABroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000469 vendor-advisoryx_refsource_CONECTIVABroken Link
- http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:022 vendor-advisoryx_refsource_MANDRAKEBroken Link
- http://www.caldera.com/support/security/advisories/CSSA-2002-014.1.txt vendor-advisoryx_refsource_CALDERABroken Link
- http://www.cert.org/advisories/CA-2002-07.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.debian.org/security/2002/dsa-122 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.kb.cert.org/vuls/id/368819 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-023.php vendor-advisoryx_refsource_MANDRAKEBroken LinkPatchVendor Advisory
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-024.php3 vendor-advisoryx_refsource_MANDRAKEBroken Link
- http://www.redhat.com/support/errata/RHSA-2002-026.html vendor-advisoryx_refsource_REDHATBroken LinkPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2002-027.html vendor-advisoryx_refsource_REDHATBroken LinkPatchVendor Advisory
- http://www.securityfocus.com/bid/4267 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-030 vendor-advisoryx_refsource_HPBroken Link
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-036 vendor-advisoryx_refsource_HPBroken Link
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0204-037 vendor-advisoryx_refsource_HPBroken Link
- https://access.redhat.com/security/cve/CVE-2002-0059 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616731 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8427 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2002-0059
- https://www.cve.org/CVERecord?id=CVE-2002-0059
Change history (0)
No recorded changes yet.