Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3381

Опубликовано: 05 мар. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

A flaw was found in Compress::Raw::Zlib. This component bundles an outdated version of the zlib compression library, which contains known security vulnerabilities. An attacker could potentially exploit these underlying zlib vulnerabilities through Compress::Raw::Zlib, leading to unspecified security impacts.

Отчет

This has been rated as moderate as the older version of zlib only has two known flaws, and one of them is a bufferoverflow that is in the contrib directory, and so are not part of zlib.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-Compress-Raw-ZlibNot affected
Red Hat Enterprise Linux 7perl-Compress-Raw-ZlibNot affected
Red Hat Enterprise Linux 8perl:5.32/perl-Compress-Raw-ZlibNot affected
Red Hat Enterprise Linux 8perl-Compress-Raw-ZlibNot affected
Red Hat Enterprise Linux 9perl-Compress-Raw-ZlibNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1104
https://bugzilla.redhat.com/show_bug.cgi?id=2444733compress-raw-zlib: Compress::Raw::Zlib: Vulnerabilities due to outdated zlib library

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
22 дня назад

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

CVSS3: 9.8
nvd
22 дня назад

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

CVSS3: 9.8
msrc
20 дней назад

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib

CVSS3: 9.8
debian
22 дня назад

Compress::Raw::Zlib versions through 2.219 for Perl use potentially in ...

CVSS3: 9.8
github
21 день назад

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-27171.

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS3