CVE-2003-0107 describes a buffer overflow vulnerability in the gzprintf function of zlib version 1.1.4. This flaw occurs when zlib is compiled without vsnprintf or when long inputs are truncated, affecting the zlib compression library. Rated with a CVSS score of 7.5, this vulnerability is considered highly severe, allowing unauthenticated attackers to cause a denial of service or potentially execute arbitrary code over the network with low attack complexity. While not listed on the KEV catalog, exploit code for this vulnerability is publicly available on ExploitDB. The CVE has garnered significant community attention with 10 mentions, indicating awareness and discussion among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.4CPE matchmatch criteria | cpe:2.3:a:zlib:zlib:1.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.