cbcvebase.
CVE-2016-9841
published 2017-05-23

CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
appleiphone_os< 1111
applemac_os_x>= 10.0.0 < 10.13.010.13.0
applemacos_high_sierra
appletvos< 11.011.0
appletvos
applewatchos< 44
applewatchos_4
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianrsync< rsync 3.1.3-6 (bookworm)rsync 3.1.3-6 (bookworm)
debianzlib< rsync 3.1.3-6 (bookworm)rsync 3.1.3-6 (bookworm)
klibc_projectklibc>= 0 < 2.0.7-1ubuntu5.22.0.7-1ubuntu5.2
klibc_projectklibc>= 0 < 2.0.10-4ubuntu0.12.0.10-4ubuntu0.1
klibc_projectklibc>= 0 < 2.0.13-4ubuntu0.12.0.13-4ubuntu0.1
klibc_projectklibc>= 0 < 2.0.3-0ubuntu1.14.04.3+esm32.0.3-0ubuntu1.14.04.3+esm3
klibc_projectklibc>= 0 < 2.0.4-8ubuntu1.16.04.4+esm22.0.4-8ubuntu1.16.04.4+esm2
klibc_projectklibc>= 0 < 2.0.4-9ubuntu2.2+esm12.0.4-9ubuntu2.2+esm1
msrcazl3_fltk_1.3.8-1_on_azure_linux_3.0
msrcazl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
netappe-series_santricity_os_controller11.0.0 – 11.70.1
netapponcommand_unified_manager<= 7.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL