CVE-2016-9843

Aliases:DEBIAN-CVE-2016-9843CGA-23xq-ggwr-mcx6CGA-2rqq-538q-mqm9CGA-2x6g-w589-9v69CGA-372j-87fw-vvmrCGA-3jpv-j8q4-38m7CGA-3m6v-v32v-hrq5CGA-57hg-6xvj-45vwCGA-58qc-j886-767rCGA-5j35-mw78-692hCGA-5x6v-p4p4-fc3qCGA-6479-mrcp-r4ppCGA-7477-52v8-5jh9CGA-793p-8q9w-7fwrCGA-7gjg-p9m9-55m7CGA-7wc6-vx8q-rwhmCGA-83pq-277v-j3grCGA-8mwj-jpmm-wjr6CGA-95q9-74jg-2hrqCGA-99rq-6p83-mvrrCGA-9q8r-3r3p-m996CGA-c534-53pp-3q3cCGA-c5q4-xjxg-9vqcCGA-cc9p-5253-hj3vCGA-cm45-m86f-86v3CGA-cp59-p3x2-724wCGA-cq37-qvxp-hj36CGA-f847-2r97-3h4rCGA-g6f4-5pmr-764pCGA-hv5q-3hh2-8f3gCGA-hx63-3f83-2664CGA-j338-rcqf-m6v8CGA-j5gq-3787-q5h2CGA-mmp8-gv4r-jhh3CGA-qp96-3pj4-f3g5CGA-r76g-7q9c-p26rCGA-r92r-98fx-2wmpCGA-r9p8-3784-gj5xCGA-rh68-53cq-mv52CGA-rr8p-rhqf-59fmCGA-rvgh-92p8-x5jhCGA-wpp5-rh99-gcw6CGA-x78v-j3gq-jwxqCGA-x9x5-pr4x-pgvxCGA-xccw-6454-wf2w
Advisory lineage Upstream: 0 Downstream: 42
Modified
Published: 23 May 2017, 03:56
Last modified:06 Aug 2024, 02:59

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
5.77% LOW
6% probability -2.22%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 May 2017, 03:56
Published
Vulnerability first disclosed
06 Aug 2024, 02:59
Last Modified
Vulnerability information updated

Description

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 5.77% Percentile: 93%

Affected Systems

  • chainguardmysql-8.0

    < 8.0.38-r0

  • chainguardmysql-8.0-client

    < 8.0.38-r0

  • chainguardmysql-8.0-dev

    < 8.0.38-r0

  • chainguardmysql-8.0-iamguarded-compat

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint-compat

    < 8.0.38-r0

  • chainguardopenjdk-11-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-17-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-21-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.53.0-r1

  • appleiphone_os

    < 11

  • applemac_os_x

    ≥ 10.0.0, < 10.13.0

  • appletvos

    < 11.0

  • applewatchos

    < 4

  • canonicalubuntu_linux

    16.04 | 18.04

  • debianrsync

    < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6

  • debianzlib

    < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3

  • debiandebian_linux

    8.0

  • mariadbmariadb

    ≥ 5.5.0, < 5.5.62 | ≥ 10.0.0, < 10.0.37 | ≥ 10.1.0, < 10.1.37 | ≥ 10.2.0, < 10.2.19 | ≥ 10.3.0, < 10.3.11

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappsnapcenter

    na

  • nodejsnode.js

    ≥ 4.0.0, ≤ 4.1.2 | ≥ 4.2.0, < 4.8.2 | ≥ 6.0.0, ≤ 6.8.1 | ≥ 6.9.0, < 6.10.2 | ≥ 7.0.0, < 7.6.0

  • opensuseleap

    42.1 | 42.2

  • opensuseopensuse

    13.2

  • oracledatabase_server

    18c

  • oraclejdk

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclejre

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclemysql

    ≥ 5.5.0, ≤ 5.5.61 | ≥ 5.6.0, ≤ 5.6.41 | ≥ 5.7.0, ≤ 5.7.23 | ≥ 8.0.0, ≤ 8.0.12

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_eus

    7.4 | 7.5

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatsatellite

    5.8

  • zlibzlib

    ≥ 1.2.0, < 1.2.9

References (34)