cbcvebase.
CVE-2016-9842
published 2017-05-23

CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Affected

55 ranges· showing 25
VendorProductVersion rangeFixed in
appleios
appleiphone_os< 1111
applemac_os_x>= 10.0.0 < 10.13.010.13.0
applemacos_high_sierra
appletvos< 11.011.0
appletvos
applewatchos< 44
applewatchos_4
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianrsync< rsync 3.1.3-6 (bookworm)rsync 3.1.3-6 (bookworm)
debianzlib< rsync 3.1.3-6 (bookworm)rsync 3.1.3-6 (bookworm)
msrcazl3_fltk_1.3.8-1_on_azure_linux_3.0
msrcazl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0
nodejsnode.js4.0.0 – 4.1.2
nodejsnode.js>= 4.2.0 < 4.8.24.8.2
nodejsnode.js6.0.0 – 6.8.1
nodejsnode.js>= 6.9.0 < 6.10.26.10.2
nodejsnode.js>= 7.0.0 < 7.6.07.6.0
opensuseleap
opensuseleap
opensuseopensuse
oracledatabase_server
oraclejdk

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH