@cR0w brb I'll just update the _gazillion_ embedded zlib libraries in ... EVERYTHING
Yeah but don't assume untgz is in there. It's old, the issue is in having to search through every single embedded system to see if _they_ include it ...
Ah. This issue was reported already three years ago and Adler pointed out that anything in contrib/ is not considered part of zlib.
Someone would have needed to clone the repo and go out of their way to also compile untgz and include somewhere. Still something that needs checking I guess, but it's not likely to exist in _many_ places.
"ioapi.c and untgz.c are in the contrib directory, and so are not part of zlib. You can contact the authors of those codes if you like, but in any case they are not vulnerabilities in zlib." - Mark Adler