CVE-2016-9841
published 2017-05-23CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
7.55%
93.8th percentile
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 11 | 11 |
| apple | mac_os_x | >= 10.0.0 < 10.13.0 | 10.13.0 |
| apple | macos_high_sierra | — | — |
| apple | tvos | < 11.0 | 11.0 |
| apple | tvos | — | — |
| apple | watchos | < 4 | 4 |
| apple | watchos_4 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | rsync | < rsync 3.1.3-6 (bookworm) | rsync 3.1.3-6 (bookworm) |
| debian | zlib | < rsync 3.1.3-6 (bookworm) | rsync 3.1.3-6 (bookworm) |
| klibc_project | klibc | >= 0 < 2.0.7-1ubuntu5.2 | 2.0.7-1ubuntu5.2 |
| klibc_project | klibc | >= 0 < 2.0.10-4ubuntu0.1 | 2.0.10-4ubuntu0.1 |
| klibc_project | klibc | >= 0 < 2.0.13-4ubuntu0.1 | 2.0.13-4ubuntu0.1 |
| klibc_project | klibc | >= 0 < 2.0.3-0ubuntu1.14.04.3+esm3 | 2.0.3-0ubuntu1.14.04.3+esm3 |
| klibc_project | klibc | >= 0 < 2.0.4-8ubuntu1.16.04.4+esm2 | 2.0.4-8ubuntu1.16.04.4+esm2 |
| klibc_project | klibc | >= 0 < 2.0.4-9ubuntu2.2+esm1 | 2.0.4-9ubuntu2.2+esm1 |
| msrc | azl3_fltk_1.3.8-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.70.1 | — |
| netapp | oncommand_unified_manager | <= 7.1 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
zlib 1.2.8 Pointer Arithmetic inffast.c numeric error (RHSA-2017:1220 / Nessus ID 96691)
vuldb·2026-07-14·CVSS 9.8
CVE-2016-9841 [CRITICAL] zlib 1.2.8 Pointer Arithmetic inffast.c numeric error (RHSA-2017:1220 / Nessus ID 96691)
A vulnerability categorized as problematic has been discovered in zlib 1.2.8. This affects an unknown function in the library zlib of the file inffast.c of the component Pointer Arithmetic. Such manipulation leads to numeric error.
This vulnerability is listed as CVE-2016-9841. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
VulDB
Apple watchOS up to 3.2.3 zlib numeric error (HT208115 / Nessus ID 96376)
vuldb·2026-07-14·CVSS 9.8
CVE-2016-9841 [CRITICAL] Apple watchOS up to 3.2.3 zlib numeric error (HT208115 / Nessus ID 96376)
A vulnerability was found in Apple watchOS up to 3.2.3. It has been declared as very critical. The impacted element is an unknown function of the component zlib. Executing a manipulation can lead to numeric error.
This vulnerability appears as CVE-2016-9841. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
VulDB
Apple iOS up to 10.3.3 zlib numeric error (HT208112 / Nessus ID 100378)
vuldb·2026-07-14·CVSS 9.8
CVE-2016-9841 [CRITICAL] Apple iOS up to 10.3.3 zlib numeric error (HT208112 / Nessus ID 100378)
A vulnerability marked as very critical has been reported in Apple iOS up to 10.3.3. This vulnerability affects unknown code of the component zlib. Performing a manipulation results in numeric error.
This vulnerability is identified as CVE-2016-9841. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
VulDB
Apple tvOS up to 10.2.2 zlib numeric error (HT208113 / Nessus ID 100378)
vuldb·2026-07-14·CVSS 9.8
CVE-2016-9841 [CRITICAL] Apple tvOS up to 10.2.2 zlib numeric error (HT208113 / Nessus ID 100378)
A vulnerability has been found in Apple tvOS up to 10.2.2 and classified as very critical. This affects an unknown part of the component zlib. This manipulation causes numeric error.
This vulnerability is tracked as CVE-2016-9841. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
VulDB
Oracle Java SE 6u161/7u151/8u144 zlib numeric error (Nessus ID 103189 / ID 371397)
vuldb·2026-07-14·CVSS 9.8
CVE-2016-9841 [CRITICAL] Oracle Java SE 6u161/7u151/8u144 zlib numeric error (Nessus ID 103189 / ID 371397)
A vulnerability was found in Oracle Java SE 6u161/7u151/8u144. It has been classified as problematic. This vulnerability affects unknown code of the component zlib. The manipulation leads to numeric error.
This vulnerability is referenced as CVE-2016-9841. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
OSV
klibc vulnerabilities
osv·2024-05-23·CVSS 8.8
CVE-2016-9840 [HIGH] klibc vulnerabilities
klibc vulnerabilities
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to c
OSV
klibc vulnerabilities
osv·2024-04-16·CVSS 8.8
CVE-2016-9840 [HIGH] klibc vulnerabilities
klibc vulnerabilities
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
GHSA
GHSA-5f8r-846v-423w: inffast
ghsa_unreviewed·2022-05-13
CVE-2016-9841 [CRITICAL] GHSA-5f8r-846v-423w: inffast
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
OSV
rsync vulnerabilities
osv·2020-02-25·CVSS 8.8
CVE-2016-9840 [HIGH] rsync vulnerabilities
rsync vulnerabilities
It was discovered that rsync incorrectly handled pointer arithmetic in zlib.
An attacker could use this issue to cause rsync to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-9840,
CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts
of negative integers in zlib. An attacker could use this issue to cause rsync
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9842)
It was discovered that rsync incorrectly handled vectors involving big-endian
CRC calculation in zlib. An attacker could use this issue to cause rsync to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
OSV
zlib vulnerabilities
osv·2020-01-22·CVSS 8.8
CVE-2016-9840 [HIGH] zlib vulnerabilities
zlib vulnerabilities
It was discovered that zlib incorrectly handled pointer arithmetic. An attacker
could use this issue to cause zlib to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
It was discovered that zlib incorrectly handled vectors involving left shifts of
negative integers. An attacker could use this issue to cause zlib to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9842)
It was discovered that zlib incorrectly handled vectors involving big-endian CRC
calculation. An attacker could use this issue to cause zlib to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
OSV
CVE-2016-9841: inffast
osv·2017-05-23·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Ubuntu
klibc vulnerabilities
vendor_ubuntu·2024-05-23·CVSS 8.8
CVE-2016-9841 [HIGH] klibc vulnerabilities
Title: klibc vulnerabilities
Summary: Several security issues were fixed in klibc.
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate op
Ubuntu
klibc vulnerabilities
vendor_ubuntu·2024-04-16·CVSS 8.8
CVE-2018-25032 [HIGH] klibc vulnerabilities
Title: klibc vulnerabilities
Summary: Several security issues were fixed in klibc.
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
Instructions: In
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2020-02-25·CVSS 8.8
CVE-2016-9840 [HIGH] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
It was discovered that rsync incorrectly handled pointer arithmetic in zlib.
An attacker could use this issue to cause rsync to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-9840,
CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts
of negative integers in zlib. An attacker could use this issue to cause rsync
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9842)
It was discovered that rsync incorrectly handled vectors involving big-endian
CRC calculation in zlib. An attacker could use this issue to cause rsync to
crash, resulting in a denial of service, or possibly execute arbitrary
Ubuntu
zlib vulnerabilities
vendor_ubuntu·2020-01-22·CVSS 8.8
CVE-2016-9840 [HIGH] zlib vulnerabilities
Title: zlib vulnerabilities
Summary: Several security issues were fixed in zlib
It was discovered that zlib incorrectly handled pointer arithmetic. An attacker
could use this issue to cause zlib to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
It was discovered that zlib incorrectly handled vectors involving left shifts of
negative integers. An attacker could use this issue to cause zlib to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9842)
It was discovered that zlib incorrectly handled vectors involving big-endian CRC
calculation. An attacker could use this issue to cause zlib to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
Instructi
Apple
CVE-2016-9841: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2016-9841
Component: CVE-2016-9841
Apple
CVE-2016-9841: watchOS 4
vendor_apple·2017-09-19·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841: watchOS 4
Apple Security Update: About the security content of watchOS 4
Product: watchOS 4
CVE: CVE-2016-9841
Component: CVE-2016-9841
Apple
CVE-2016-9841: tvOS 11
vendor_apple·2017-09-19·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2016-9841
Component: CVE-2016-9841
Apple
CVE-2016-9841: iOS 11
vendor_apple·2017-09-19·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2016-9841
Component: CVE-2016-9841
Microsoft
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
vendor_msrc·2017-05-09·CVSS 9.8
CVE-2016-9841 [CRITICAL] inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
microfocus: microfocus
Cus
Red Hat
zlib: Out-of-bounds pointer arithmetic in inffast.c
vendor_redhat·2016-09-22·CVSS 9.8
CVE-2016-9841 [CRITICAL] zlib: Out-of-bounds pointer arithmetic in inffast.c
zlib: Out-of-bounds pointer arithmetic in inffast.c
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Package: zlib (Red Hat Enterprise Linux 5) - Not affected
Package: zlib (Red Hat Enterprise Linux 6) - Not affected
Package: zlib (Red Hat Enterprise Linux 7) - Not affected
Package: zlib (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: zlib (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: zlib (Red Hat JBoss Enterprise Web Server 1) - Not affected
Package: zlib (Red Hat JBoss Enterprise Web Server 2) - Not affected
Package: zlib (Red Hat JBoss Enterprise Web Server 3) - Not affected
Debian
CVE-2016-9841: rsync - inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif...
vendor_debian·2016·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841: rsync - inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif...
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Scope: local
bookworm: resolved (fixed in 3.1.3-6)
bullseye: resolved (fixed in 3.1.3-6)
forky: resolved (fixed in 3.1.3-6)
sid: resolved (fixed in 3.1.3-6)
trixie: resolved (fixed in 3.1.3-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9841 zlib: Out-of-bounds pointer arithmetic in inffast.c
bugzilla·2016-12-07·CVSS 9.8
CVE-2016-9841 [CRITICAL] CVE-2016-9841 zlib: Out-of-bounds pointer arithmetic in inffast.c
CVE-2016-9841 zlib: Out-of-bounds pointer arithmetic in inffast.c
An old inffast.c optimization turns out to not be optimal anymore
with modern compilers, and furthermore was not compliant with the
C standard, for which decrementing a pointer before its allocated
memory is undefined.
External References:
https://wiki.mozilla.org/images/0/09/Zlib-report.pdf
https://docs.google.com/document/d/10i1KZS5so8xDqH2rplRa2xet0tyTvvJlLbQQmZIUIKE/edit#heading=h.t13tvnx4loq7
Upstream patch:
https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecb
CVE assignment:
http://seclists.org/oss-sec/2016/q4/602
Discussion:
Created zlib tracking bugs for this issue:
Affects: fedora-all [bug 1402352]
---
This issue has been addressed in the following products:
Red Hat Enterprise
Bugzilla
CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
bugzilla·2016-12-07·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-9841 ImageMagick: throwing of exceptions in psd handling
bugzilla·2016-06-07·CVSS 9.8
CVE-2014-9841 [CRITICAL] CVE-2014-9841 ImageMagick: throwing of exceptions in psd handling
CVE-2014-9841 ImageMagick: throwing of exceptions in psd handling
Fixed throwing of exceptions in psd handling.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=f9ef11671c41da4cf973d0d880af1cdfbd127860
http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2016/12/05/21http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/95131http://www.securitytracker.com/id/1039427http://www.securitytracker.com/id/1039596https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3453https://bugzilla.redhat.com/show_bug.cgi?id=1402346https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecbhttps://lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlhttps://security.gentoo.org/glsa/201701-56https://security.gentoo.org/glsa/202007-54https://security.netapp.com/advisory/ntap-20171019-0001/https://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://usn.ubuntu.com/4246-1/https://usn.ubuntu.com/4292-1/https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibhttps://wiki.mozilla.org/images/0/09/Zlib-report.pdfhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2016/12/05/21http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/95131http://www.securitytracker.com/id/1039427http://www.securitytracker.com/id/1039596https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3453https://bugzilla.redhat.com/show_bug.cgi?id=1402346https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecbhttps://lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlhttps://security.gentoo.org/glsa/201701-56https://security.gentoo.org/glsa/202007-54https://security.netapp.com/advisory/ntap-20171019-0001/https://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://usn.ubuntu.com/4246-1/https://usn.ubuntu.com/4292-1/https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibhttps://wiki.mozilla.org/images/0/09/Zlib-report.pdfhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-470355.html
2017-05-23
Published