CVE-2016-9840

Red Hat Security Advisory: OpenShift Container Platform 4.17.32 bug fix and security update

Beschreibung

In `inftrees.c` von zlib 1.2.8 könnten Kontext-abhängige Angreifer einen nicht näher bezeichneten Einfluss ausnutzen, indem sie fehlerhaftes Zeigerarithmetik verwenden.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.8
Quelle: nvd-v3
91.4 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
4.8 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2025-06-04 09:19 UTC

Betroffene Betriebssysteme

  • linux

    debian / debian_linux8.0

  • linux

    redhat / enterprise_linux_desktop6.0

  • linux

    redhat / enterprise_linux_desktop7.0

  • linux

    redhat / enterprise_linux_eus7.4

  • linux

    redhat / enterprise_linux_eus7.5

  • linux

    redhat / enterprise_linux_server6.0

  • linux

    redhat / enterprise_linux_server7.0

  • linux

    redhat / enterprise_linux_workstation6.0

  • linux

    redhat / enterprise_linux_workstation7.0

  • linux

    opensuse / leap42.1

  • linux

    opensuse / leap42.2

  • linux

    opensuse / opensuse13.2

  • linux

    canonical / ubuntu_linux16.04

  • linux

    canonical / ubuntu_linux18.04

  • macos

    apple / mac_os_x

  • mobile

    apple / iphone_os

  • other

    apple / tvos

  • other

    apple / watchos

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • boost

    boost1.78.0

  • go

    github.com/openshift/console

  • go

    golang.org/x/net

  • go

    golang.org/x/oauth2

  • nodejs

    node.js4.0.0 – 4.1.2

  • nodejs

    node.js4.2.0 – 4.8.2

  • nodejs

    node.js6.0.0 – 6.8.1

  • nodejs

    node.js6.9.0 – 6.10.2

  • nodejs

    node.js7.0.0 – 7.6.0

  • oracle

    database_server

  • oracle

    jdk

  • oracle

    jre

  • oracle

    mysql5.5.0 – 5.5.61

  • oracle

    mysql5.6.0 – 5.6.41

  • oracle

    mysql5.7.0 – 5.7.23

  • oracle

    mysql8.0.0 – 8.0.12

  • redhat

    satellite

  • zlib

    zlib1.2.0.6 – 1.2.9

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2016-9840