CVE-2016-9841

Zlib 1.2.11

criticalEPSS 7.5%

Description

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Metrics

Severity
critical
no public PoC known
9.8
Source: nvd-v3
94.2 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
7.5 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2017-05-23 03:56 UTC

Affected operating systems

  • linux

    debian / debian_linux8.0

  • linux

    redhat / enterprise_linux_desktop6.0

  • linux

    redhat / enterprise_linux_desktop7.0

  • linux

    redhat / enterprise_linux_eus7.4

  • linux

    redhat / enterprise_linux_eus7.5

  • linux

    redhat / enterprise_linux_server6.0

  • linux

    redhat / enterprise_linux_server7.0

  • linux

    redhat / enterprise_linux_workstation6.0

  • linux

    redhat / enterprise_linux_workstation7.0

  • linux

    opensuse / leap42.1

  • linux

    opensuse / leap42.2

  • linux

    opensuse / opensuse13.2

  • linux

    canonical / ubuntu_linux16.04

  • linux

    canonical / ubuntu_linux18.04

  • macos

    apple / mac_os_x

  • mobile

    apple / iphone_os

  • other

    apple / tvos

  • other

    apple / watchos

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • netapp

    active_iq_unified_manager7.3

  • netapp

    active_iq_unified_manager9.5

  • netapp

    cloud_backup

  • netapp

    e-series_santricity_management

  • netapp

    e-series_santricity_os_controller11.0.0 – 11.70.1

  • netapp

    e-series_santricity_storage_manager

  • netapp

    e-series_santricity_web_services

  • netapp

    hci_storage_node

  • netapp

    oncommand_balance

  • netapp

    oncommand_insight

  • netapp

    oncommand_performance_manager

  • netapp

    oncommand_shift

  • netapp

    oncommand_unified_manager7.1

  • netapp

    oncommand_unified_manager

  • netapp

    oncommand_workflow_automation

  • netapp

    snapmanager

  • netapp

    solidfire

  • netapp

    steelstore_cloud_integrated_storage

  • netapp

    storage_replication_adapter_for_clustered_data_ontap

  • netapp

    symantec_netbackup

  • netapp

    vasa_provider_for_clustered_data_ontap7.2

  • netapp

    virtual_storage_console

  • nodejs

    node.js4.0.0 – 4.1.2

  • nodejs

    node.js4.2.0 – 4.8.2

References & sources

IDCVE-2016-9841