First published: Wed Dec 07 2016(Updated: )
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Credit: CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 security@opentext.com meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/zlib | <1.2.9 | 1.2.9 |
debian/rsync | 3.2.3-4+deb11u1 3.2.3-4+deb11u3 3.2.7-1 3.2.7-1+deb12u2 3.3.0+ds1-4 | |
debian/zlib | 1:1.2.11.dfsg-2+deb11u2 1:1.2.13.dfsg-1 1:1.3.dfsg+really1.3.1-1 | |
tvOS | <11 | 11 |
macOS High Sierra | <10.13 | 10.13 |
Apple iOS, iPadOS, and watchOS | <11 | 11 |
Apple iOS, iPadOS, and watchOS | <4 | 4 |
zlib | >=1.2.0.6<1.2.9 | |
openSUSE | =42.1 | |
openSUSE | =42.2 | |
openSUSE | =13.2 | |
Debian | =8.0 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Oracle Database | =18c | |
Oracle JDK 6 | =1.6.0-update161 | |
Oracle JDK 6 | =1.7.0-update151 | |
Oracle JDK 6 | =1.8.0-update144 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update161 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update151 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update144 | |
MySQL | >=5.5.0<=5.5.61 | |
MySQL | >=5.6.0<=5.6.41 | |
MySQL | >=5.7.0<=5.7.23 | |
MySQL | >=8.0.0<=8.0.12 | |
redhat satellite | =5.8 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =7.4 | |
redhat enterprise Linux eus | =7.5 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
iOS | <11 | |
Apple iOS and macOS | >=10.0.0<10.13.0 | |
tvOS | <11.0 | |
Apple iOS, iPadOS, and watchOS | <4 | |
Node.js | >=4.0.0<=4.1.2 | |
Node.js | >=4.2.0<4.8.2 | |
Node.js | >=6.0.0<=6.8.1 | |
Node.js | >=6.9.0<6.10.2 | |
Node.js | >=7.0.0<7.6.0 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=17.1.0<=17.1.2 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=8.2.0<=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2016-9840 has been classified with a severity that could allow attackers to exploit improper pointer arithmetic leading to unspecified impact.
To fix CVE-2016-9840, update zlib to version 1.2.9 or later, or apply vendor-specific patches as applicable.
CVE-2016-9840 affects zlib versions prior to 1.2.9 and several operating systems including older versions of iOS, macOS, and various Linux distributions.
CVE-2016-9840 may allow context-dependent attackers to exploit applications using the vulnerable zlib library, potentially leading to remote attacks.
Exploitation of CVE-2016-9840 could result in application crashes or arbitrary code execution due to improper handling of pointers.