CVE-2016-9841

Advisory lineage Upstream: 0 Downstream: 35
Modified
Published: 23 May 2017, 03:56
Last modified:06 Aug 2024, 02:59

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
13.49% MEDIUM
13% probability -6.79%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 May 2017, 03:56
Published
Vulnerability first disclosed
06 Aug 2024, 02:59
Last Modified
Vulnerability information updated

Description

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 13.49% Percentile: 94%

Affected Systems

  • appleiphone_os

    < 11

  • applemac_os_x

    ≥ 10.0.0, < 10.13.0

  • appletvos

    < 11.0

  • applewatchos

    < 4

  • canonicalubuntu_linux

    16.04 | 18.04

  • debiandebian_linux

    8.0

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netappcloud_backup

    na

  • netappe-series_santricity_management

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.1

  • netappe-series_santricity_storage_manager

    na

  • netappe-series_santricity_web_services

    na

  • netapphci_storage_node

    na

  • netapponcommand_balance

    na

  • netapponcommand_insight

    na

  • netapponcommand_performance_manager

    na

  • netapponcommand_shift

    na

  • netapponcommand_unified_manager

    ≤ 7.1 | na

  • netapponcommand_workflow_automation

    na

  • netappsnapmanager

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • netappstorage_replication_adapter_for_clustered_data_ontap

    na

  • netappsymantec_netbackup

    na

  • netappvasa_provider_for_clustered_data_ontap

    ≥ 7.2

  • netappvirtual_storage_console

    na

  • nodejsnode.js

    ≥ 4.0.0, ≤ 4.1.2 | ≥ 4.2.0, < 4.8.2 | ≥ 6.0.0, ≤ 6.8.1 | ≥ 6.9.0, < 6.10.2 | ≥ 7.0.0, < 7.6.0

  • opensuseleap

    42.1 | 42.2

  • opensuseopensuse

    13.2

  • oracledatabase_server

    18c

  • oraclejdk

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclejre

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclemysql

    ≥ 5.5.0, ≤ 5.5.61 | ≥ 5.6.0, ≤ 5.6.41 | ≥ 5.7.0, ≤ 5.7.23 | ≥ 8.0.0, ≤ 8.0.12

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_eus

    7.4 | 7.5

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatsatellite

    5.8

  • zlibzlib

    ≥ 1.2.0, < 1.2.9

References (33)