CVE-2016-9840
published 2017-05-23CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.79%
91.0th percentile
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 11 | 11 |
| apple | mac_os_x | >= 10.0.0 < 10.13.0 | 10.13.0 |
| apple | macos_high_sierra | — | — |
| apple | tvos | < 11.0 | 11.0 |
| apple | tvos | — | — |
| apple | watchos | < 4 | 4 |
| apple | watchos_4 | — | — |
| boost | boost | < 1.78.0 | 1.78.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | rsync | < rsync 3.1.3-6 (bookworm) | rsync 3.1.3-6 (bookworm) |
| debian | zlib | < rsync 3.1.3-6 (bookworm) | rsync 3.1.3-6 (bookworm) |
| klibc_project | klibc | >= 0 < 2.0.7-1ubuntu5.2 | 2.0.7-1ubuntu5.2 |
| klibc_project | klibc | >= 0 < 2.0.10-4ubuntu0.1 | 2.0.10-4ubuntu0.1 |
| klibc_project | klibc | >= 0 < 2.0.13-4ubuntu0.1 | 2.0.13-4ubuntu0.1 |
| klibc_project | klibc | >= 0 < 2.0.3-0ubuntu1.14.04.3+esm3 | 2.0.3-0ubuntu1.14.04.3+esm3 |
| klibc_project | klibc | >= 0 < 2.0.4-8ubuntu1.16.04.4+esm2 | 2.0.4-8ubuntu1.16.04.4+esm2 |
| klibc_project | klibc | >= 0 < 2.0.4-9ubuntu2.2+esm1 | 2.0.4-9ubuntu2.2+esm1 |
| msrc | azl3_fltk_1.3.8-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_boost_1.76.0-4_on_cbl_mariner_2.0 | — | — |
| nodejs | node.js | 4.0.0 – 4.1.2 | — |
| nodejs | node.js | >= 4.2.0 < 4.8.2 | 4.8.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
klibc vulnerabilities
osv·2024-05-23·CVSS 8.8
CVE-2016-9840 [HIGH] klibc vulnerabilities
klibc vulnerabilities
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to c
OSV
klibc vulnerabilities
osv·2024-04-16·CVSS 8.8
CVE-2016-9840 [HIGH] klibc vulnerabilities
klibc vulnerabilities
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
GHSA
GHSA-wrj6-35fr-8xw5: inftrees
ghsa_unreviewed·2022-05-13
CVE-2016-9840 [HIGH] GHSA-wrj6-35fr-8xw5: inftrees
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
OSV
rsync vulnerabilities
osv·2020-02-25·CVSS 8.8
CVE-2016-9840 [HIGH] rsync vulnerabilities
rsync vulnerabilities
It was discovered that rsync incorrectly handled pointer arithmetic in zlib.
An attacker could use this issue to cause rsync to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-9840,
CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts
of negative integers in zlib. An attacker could use this issue to cause rsync
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9842)
It was discovered that rsync incorrectly handled vectors involving big-endian
CRC calculation in zlib. An attacker could use this issue to cause rsync to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
OSV
zlib vulnerabilities
osv·2020-01-22·CVSS 8.8
CVE-2016-9840 [HIGH] zlib vulnerabilities
zlib vulnerabilities
It was discovered that zlib incorrectly handled pointer arithmetic. An attacker
could use this issue to cause zlib to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
It was discovered that zlib incorrectly handled vectors involving left shifts of
negative integers. An attacker could use this issue to cause zlib to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9842)
It was discovered that zlib incorrectly handled vectors involving big-endian CRC
calculation. An attacker could use this issue to cause zlib to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
OSV
CVE-2016-9840: inftrees
osv·2017-05-23·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840: inftrees
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Ubuntu
klibc vulnerabilities
vendor_ubuntu·2024-05-23·CVSS 8.8
CVE-2016-9841 [HIGH] klibc vulnerabilities
Title: klibc vulnerabilities
Summary: Several security issues were fixed in klibc.
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate op
Ubuntu
klibc vulnerabilities
vendor_ubuntu·2024-04-16·CVSS 8.8
CVE-2018-25032 [HIGH] klibc vulnerabilities
Title: klibc vulnerabilities
Summary: Several security issues were fixed in klibc.
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
Instructions: In
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2020-02-25·CVSS 8.8
CVE-2016-9840 [HIGH] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
It was discovered that rsync incorrectly handled pointer arithmetic in zlib.
An attacker could use this issue to cause rsync to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-9840,
CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts
of negative integers in zlib. An attacker could use this issue to cause rsync
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9842)
It was discovered that rsync incorrectly handled vectors involving big-endian
CRC calculation in zlib. An attacker could use this issue to cause rsync to
crash, resulting in a denial of service, or possibly execute arbitrary
Ubuntu
zlib vulnerabilities
vendor_ubuntu·2020-01-22·CVSS 8.8
CVE-2016-9840 [HIGH] zlib vulnerabilities
Title: zlib vulnerabilities
Summary: Several security issues were fixed in zlib
It was discovered that zlib incorrectly handled pointer arithmetic. An attacker
could use this issue to cause zlib to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
It was discovered that zlib incorrectly handled vectors involving left shifts of
negative integers. An attacker could use this issue to cause zlib to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9842)
It was discovered that zlib incorrectly handled vectors involving big-endian CRC
calculation. An attacker could use this issue to cause zlib to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
Instructi
Apple
CVE-2016-9840: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2016-9840
Component: CVE-2016-9840
Apple
CVE-2016-9840: iOS 11
vendor_apple·2017-09-19·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2016-9840
Component: CVE-2016-9840
Apple
CVE-2016-9840: watchOS 4
vendor_apple·2017-09-19·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840: watchOS 4
Apple Security Update: About the security content of watchOS 4
Product: watchOS 4
CVE: CVE-2016-9840
Component: CVE-2016-9840
Apple
CVE-2016-9840: tvOS 11
vendor_apple·2017-09-19·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2016-9840
Component: CVE-2016-9840
Microsoft
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
vendor_msrc·2017-05-09·CVSS 8.8
CVE-2016-9840 [HIGH] inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
microfocus: microfocus
Cu
Red Hat
zlib: Out-of-bound pointer arithmetic in inftrees.c
vendor_redhat·2016-09-22·CVSS 8.8
CVE-2016-9840 [HIGH] CWE-125 zlib: Out-of-bound pointer arithmetic in inftrees.c
zlib: Out-of-bound pointer arithmetic in inftrees.c
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
A vulnerability was discovered in the inftrees.c file of zlib. Pointer arithmetic operations violate the C standard by subtracting an offset from an array pointer before its allocated memory, leading to undefined behavior.
Statement: While this undefined behavior does not currently manifest as an exploitable issue on Red Hat Enterprise Linux systems using GCC compilers, it could become problematic with future compiler implementations. This flaw affects various Java packages in Red Hat Enterprise Linux 6 and 7, but native zlib packages in Red Hat Enterprise Linux are not impacted due to the specific comp
Debian
CVE-2016-9840: rsync - inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspeci...
vendor_debian·2016·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840: rsync - inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspeci...
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Scope: local
bookworm: resolved (fixed in 3.1.3-6)
bullseye: resolved (fixed in 3.1.3-6)
forky: resolved (fixed in 3.1.3-6)
sid: resolved (fixed in 3.1.3-6)
trixie: resolved (fixed in 3.1.3-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9840 zlib: Out-of-bound pointer arithmetic in inftrees.c
bugzilla·2016-12-07·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840 zlib: Out-of-bound pointer arithmetic in inftrees.c
CVE-2016-9840 zlib: Out-of-bound pointer arithmetic in inftrees.c
inftrees.c was subtracting an offset from a pointer to an array,
in order to provide a pointer that allowed indexing starting at
the offset. This is not compliant with the C standard, for which
the behavior of a pointer decremented before its allocated memory
is undefined.
External References:
https://wiki.mozilla.org/images/0/09/Zlib-report.pdf
https://docs.google.com/document/d/10i1KZS5so8xDqH2rplRa2xet0tyTvvJlLbQQmZIUIKE/edit#heading=h.t13tvnx4loq7
Upstream patch:
https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0
CVE assignment:
http://seclists.org/oss-sec/2016/q4/602
Discussion:
Created zlib tracking bugs for this issue:
Affects: fedora-all [bug 1402352]
---
This issue has been ad
Bugzilla
CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
bugzilla·2016-12-07·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-9840 ImageMagick: out of bound access in palm file
bugzilla·2016-06-07·CVSS 5.5
CVE-2014-9840 [MEDIUM] CVE-2014-9840 ImageMagick: out of bound access in palm file
CVE-2014-9840 ImageMagick: out of bound access in palm file
Fix an out of bound access in palm file.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=1fe9bcf765411cd8c173443a698659bfe5ed5c8c
http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2016/12/05/21http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/95131http://www.securitytracker.com/id/1039427https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3453https://bugzilla.redhat.com/show_bug.cgi?id=1402345https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0https://lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlhttps://security.gentoo.org/glsa/201701-56https://security.gentoo.org/glsa/202007-54https://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://usn.ubuntu.com/4246-1/https://usn.ubuntu.com/4292-1/https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibhttps://wiki.mozilla.org/images/0/09/Zlib-report.pdfhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2016/12/05/21http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/95131http://www.securitytracker.com/id/1039427https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3453https://bugzilla.redhat.com/show_bug.cgi?id=1402345https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0https://lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlhttps://security.gentoo.org/glsa/201701-56https://security.gentoo.org/glsa/202007-54https://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://usn.ubuntu.com/4246-1/https://usn.ubuntu.com/4292-1/https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibhttps://wiki.mozilla.org/images/0/09/Zlib-report.pdfhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-470355.html
2017-05-23
Published