CVE-2016-9842
published 2017-05-23CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of…
PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
5.20%
91.6th percentile
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 11 | 11 |
| apple | mac_os_x | >= 10.0.0 < 10.13.0 | 10.13.0 |
| apple | macos_high_sierra | — | — |
| apple | tvos | < 11.0 | 11.0 |
| apple | tvos | — | — |
| apple | watchos | < 4 | 4 |
| apple | watchos_4 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | rsync | < rsync 3.1.3-6 (bookworm) | rsync 3.1.3-6 (bookworm) |
| debian | zlib | < rsync 3.1.3-6 (bookworm) | rsync 3.1.3-6 (bookworm) |
| msrc | azl3_fltk_1.3.8-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rubygem-mini_portile2_2.8.4-1_on_azure_linux_3.0 | — | — |
| nodejs | node.js | 4.0.0 – 4.1.2 | — |
| nodejs | node.js | >= 4.2.0 < 4.8.2 | 4.8.2 |
| nodejs | node.js | 6.0.0 – 6.8.1 | — |
| nodejs | node.js | >= 6.9.0 < 6.10.2 | 6.10.2 |
| nodejs | node.js | >= 7.0.0 < 7.6.0 | 7.6.0 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | database_server | — | — |
| oracle | jdk | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsync vulnerabilities
vendor_ubuntu·2020-02-25·CVSS 8.8
CVE-2016-9840 [HIGH] rsync vulnerabilities
Title: rsync vulnerabilities
Summary: Several security issues were fixed in rsync.
It was discovered that rsync incorrectly handled pointer arithmetic in zlib.
An attacker could use this issue to cause rsync to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-9840,
CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts
of negative integers in zlib. An attacker could use this issue to cause rsync
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9842)
It was discovered that rsync incorrectly handled vectors involving big-endian
CRC calculation in zlib. An attacker could use this issue to cause rsync to
crash, resulting in a denial of service, or possibly execute arbitrary
Ubuntu
zlib vulnerabilities
vendor_ubuntu·2020-01-22·CVSS 8.8
CVE-2016-9840 [HIGH] zlib vulnerabilities
Title: zlib vulnerabilities
Summary: Several security issues were fixed in zlib
It was discovered that zlib incorrectly handled pointer arithmetic. An attacker
could use this issue to cause zlib to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
It was discovered that zlib incorrectly handled vectors involving left shifts of
negative integers. An attacker could use this issue to cause zlib to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9842)
It was discovered that zlib incorrectly handled vectors involving big-endian CRC
calculation. An attacker could use this issue to cause zlib to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
Instructi
Apple
CVE-2016-9842: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2016-9842
Component: CVE-2016-9842
Apple
CVE-2016-9842: watchOS 4
vendor_apple·2017-09-19·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842: watchOS 4
Apple Security Update: About the security content of watchOS 4
Product: watchOS 4
CVE: CVE-2016-9842
Component: CVE-2016-9842
Apple
CVE-2016-9842: iOS 11
vendor_apple·2017-09-19·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2016-9842
Component: CVE-2016-9842
Apple
CVE-2016-9842: tvOS 11
vendor_apple·2017-09-19·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2016-9842
Component: CVE-2016-9842
Microsoft
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact
vendor_msrc·2017-05-09·CVSS 8.8
CVE-2016-9842 [HIGH] The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
microfocus: microfocus
Customer Action R
Red Hat
zlib: Undefined left shift of negative number
vendor_redhat·2016-09-06·CVSS 8.8
CVE-2016-9842 [HIGH] zlib: Undefined left shift of negative number
zlib: Undefined left shift of negative number
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
Package: zlib (Red Hat Enterprise Linux 5) - Not affected
Package: zlib (Red Hat Enterprise Linux 6) - Not affected
Package: zlib (Red Hat Enterprise Linux 7) - Not affected
Package: zlib (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: zlib (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: zlib (Red Hat JBoss Enterprise Web Server 1) - Not affected
Package: zlib (Red Hat JBoss Enterprise Web Server 2) - Not affected
Package: zlib (Red Hat JBoss Enterprise Web Server 3) - Not affected
Debian
CVE-2016-9842: rsync - The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependen...
vendor_debian·2016·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842: rsync - The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependen...
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
Scope: local
bookworm: resolved (fixed in 3.1.3-6)
bullseye: resolved (fixed in 3.1.3-6)
forky: resolved (fixed in 3.1.3-6)
sid: resolved (fixed in 3.1.3-6)
trixie: resolved (fixed in 3.1.3-6)
VulDB
Apple tvOS up to 10.2.2 zlib numeric error (HT208113 / Nessus ID 100378)
vuldb·2026-07-14·CVSS 8.8
CVE-2016-9842 [HIGH] Apple tvOS up to 10.2.2 zlib numeric error (HT208113 / Nessus ID 100378)
A vulnerability was found in Apple tvOS up to 10.2.2 and classified as very critical. This vulnerability affects unknown code of the component zlib. Such manipulation leads to numeric error.
This vulnerability is listed as CVE-2016-9842. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
VulDB
Apple watchOS up to 3.2.3 zlib numeric error (HT208115 / Nessus ID 96376)
vuldb·2026-07-14·CVSS 8.8
CVE-2016-9842 [HIGH] Apple watchOS up to 3.2.3 zlib numeric error (HT208115 / Nessus ID 96376)
A vulnerability was found in Apple watchOS up to 3.2.3. It has been rated as very critical. This affects an unknown function of the component zlib. The manipulation leads to numeric error.
This vulnerability is traded as CVE-2016-9842. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
VulDB
Apple iOS up to 10.3.3 zlib numeric error (HT208112 / Nessus ID 100378)
vuldb·2026-07-14·CVSS 8.8
CVE-2016-9842 [HIGH] Apple iOS up to 10.3.3 zlib numeric error (HT208112 / Nessus ID 100378)
A vulnerability described as very critical has been identified in Apple iOS up to 10.3.3. This issue affects some unknown processing of the component zlib. Executing a manipulation can lead to numeric error.
This vulnerability is tracked as CVE-2016-9842. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
VulDB
zlib 1.2.8 inflate.c inflateMark numeric error (RHSA-2017:1220 / Nessus ID 96691)
vuldb·2026-07-14·CVSS 8.8
CVE-2016-9842 [HIGH] zlib 1.2.8 inflate.c inflateMark numeric error (RHSA-2017:1220 / Nessus ID 96691)
A vulnerability identified as problematic has been detected in zlib 1.2.8. This impacts the function inflateMark in the library zlib of the file inflate.c. Performing a manipulation results in numeric error.
This vulnerability is cataloged as CVE-2016-9842. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-3686-jjcf-4w27: The inflateMark function in inflate
ghsa_unreviewed·2022-05-13
CVE-2016-9842 [HIGH] CWE-1335 GHSA-3686-jjcf-4w27: The inflateMark function in inflate
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
OSV
rsync vulnerabilities
osv·2020-02-25·CVSS 8.8
CVE-2016-9840 [HIGH] rsync vulnerabilities
rsync vulnerabilities
It was discovered that rsync incorrectly handled pointer arithmetic in zlib.
An attacker could use this issue to cause rsync to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-9840,
CVE-2016-9841)
It was discovered that rsync incorrectly handled vectors involving left shifts
of negative integers in zlib. An attacker could use this issue to cause rsync
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-9842)
It was discovered that rsync incorrectly handled vectors involving big-endian
CRC calculation in zlib. An attacker could use this issue to cause rsync to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
OSV
zlib vulnerabilities
osv·2020-01-22·CVSS 8.8
CVE-2016-9840 [HIGH] zlib vulnerabilities
zlib vulnerabilities
It was discovered that zlib incorrectly handled pointer arithmetic. An attacker
could use this issue to cause zlib to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
It was discovered that zlib incorrectly handled vectors involving left shifts of
negative integers. An attacker could use this issue to cause zlib to
crash, resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9842)
It was discovered that zlib incorrectly handled vectors involving big-endian CRC
calculation. An attacker could use this issue to cause zlib to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-9843)
OSV
CVE-2016-9842: The inflateMark function in inflate
osv·2017-05-23·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842: The inflateMark function in inflate
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9842 zlib: Undefined left shift of negative number
bugzilla·2016-12-07·CVSS 8.8
CVE-2016-9842 [HIGH] CVE-2016-9842 zlib: Undefined left shift of negative number
CVE-2016-9842 zlib: Undefined left shift of negative number
The C standard says that bit shifts of negative integers is undefined.
External References:
https://wiki.mozilla.org/images/0/09/Zlib-report.pdf
https://docs.google.com/document/d/10i1KZS5so8xDqH2rplRa2xet0tyTvvJlLbQQmZIUIKE/edit#heading=h.t13tvnx4loq7
Upstream patches:
https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958
https://github.com/madler/zlib/commit/2edb94a3025d288dc251bc6cbb2c02e60fbd7438
CVE assignment:
http://seclists.org/oss-sec/2016/q4/602
Discussion:
Created zlib tracking bugs for this issue:
Affects: fedora-all [bug 1402352]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:1222 https://access.redhat.com/errat
Bugzilla
CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
bugzilla·2016-12-07·CVSS 8.8
CVE-2016-9840 [HIGH] CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 zlib: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2014-9842 ImageMagick: memory leak in psd handling
bugzilla·2016-06-07·CVSS 7.5
CVE-2014-9842 [HIGH] CVE-2014-9842 ImageMagick: memory leak in psd handling
CVE-2014-9842 ImageMagick: memory leak in psd handling
Fixed a memory leak in psd handling.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=f9ef11671c41da4cf973d0d880af1cdfbd127860
http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2016/12/05/21http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/95131http://www.securitytracker.com/id/1039427https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3453https://bugzilla.redhat.com/show_bug.cgi?id=1402348https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958https://lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlhttps://security.gentoo.org/glsa/201701-56https://security.gentoo.org/glsa/202007-54https://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://usn.ubuntu.com/4246-1/https://usn.ubuntu.com/4292-1/https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibhttps://wiki.mozilla.org/images/0/09/Zlib-report.pdfhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2016/12/05/21http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/95131http://www.securitytracker.com/id/1039427https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3047https://access.redhat.com/errata/RHSA-2017:3453https://bugzilla.redhat.com/show_bug.cgi?id=1402348https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958https://lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlhttps://security.gentoo.org/glsa/201701-56https://security.gentoo.org/glsa/202007-54https://support.apple.com/HT208112https://support.apple.com/HT208113https://support.apple.com/HT208115https://support.apple.com/HT208144https://usn.ubuntu.com/4246-1/https://usn.ubuntu.com/4292-1/https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlibhttps://wiki.mozilla.org/images/0/09/Zlib-report.pdfhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-470355.html
2017-05-23
Published