CVE-2016-9841

Zlib 1.2.11

criticalEPSS 7.5 %

Beschreibung

In `inffast.c` von zlib 1.2.8 könnten kontextabhängige Angreifer einen nicht näher bezeichneten Einfluss ausüben, indem sie fehlerhaftes Zeigerarithmetik nutzen. Source: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-1000365

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
94.2 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
7.5 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2017-05-23 03:56 UTC

Betroffene Betriebssysteme

  • linux

    debian / debian_linux8.0

  • linux

    redhat / enterprise_linux_desktop6.0

  • linux

    redhat / enterprise_linux_desktop7.0

  • linux

    redhat / enterprise_linux_eus7.4

  • linux

    redhat / enterprise_linux_eus7.5

  • linux

    redhat / enterprise_linux_server6.0

  • linux

    redhat / enterprise_linux_server7.0

  • linux

    redhat / enterprise_linux_workstation6.0

  • linux

    redhat / enterprise_linux_workstation7.0

  • linux

    opensuse / leap42.1

  • linux

    opensuse / leap42.2

  • linux

    opensuse / opensuse13.2

  • linux

    canonical / ubuntu_linux16.04

  • linux

    canonical / ubuntu_linux18.04

  • macos

    apple / mac_os_x

  • mobile

    apple / iphone_os

  • other

    apple / tvos

  • other

    apple / watchos

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • netapp

    active_iq_unified_manager7.3

  • netapp

    active_iq_unified_manager9.5

  • netapp

    cloud_backup

  • netapp

    e-series_santricity_management

  • netapp

    e-series_santricity_os_controller11.0.0 – 11.70.1

  • netapp

    e-series_santricity_storage_manager

  • netapp

    e-series_santricity_web_services

  • netapp

    hci_storage_node

  • netapp

    oncommand_balance

  • netapp

    oncommand_insight

  • netapp

    oncommand_performance_manager

  • netapp

    oncommand_shift

  • netapp

    oncommand_unified_manager7.1

  • netapp

    oncommand_unified_manager

  • netapp

    oncommand_workflow_automation

  • netapp

    snapmanager

  • netapp

    solidfire

  • netapp

    steelstore_cloud_integrated_storage

  • netapp

    storage_replication_adapter_for_clustered_data_ontap

  • netapp

    symantec_netbackup

  • netapp

    vasa_provider_for_clustered_data_ontap7.2

  • netapp

    virtual_storage_console

  • nodejs

    node.js4.0.0 – 4.1.2

  • nodejs

    node.js4.2.0 – 4.8.2

Quellen & Referenzen

IDCVE-2016-9841