9.8

CVE-2016-9841

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zlib ≫ Zlib Version >= 1.2.0 < 1.2.9
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Leap Version 42.2
Opensuse ≫ Opensuse Version 13.2
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Oracle ≫ Database Server Version 18c
Oracle ≫ Jdk Version 1.6.0 Update update161
Oracle ≫ Jdk Version 1.7.0 Update update151
Oracle ≫ Jdk Version 1.8.0 Update update144
Oracle ≫ Jre Version 1.6.0 Update update161
Oracle ≫ Jre Version 1.7.0 Update update151
Oracle ≫ Jre Version 1.8.0 Update update144
Oracle ≫ Mysql Version >= 5.5.0 <= 5.5.61
Oracle ≫ Mysql Version >= 5.6.0 <= 5.6.41
Oracle ≫ Mysql Version >= 5.7.0 <= 5.7.23
Oracle ≫ Mysql Version >= 8.0.0 <= 8.0.12
Redhat ≫ Satellite Version 5.8
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Apple ≫ iPhone OS Version < 11
Apple ≫ macOS X Version >= 10.0.0 < 10.13.0
Apple ≫ tvOS Version < 11.0
Apple ≫ watchOS Version < 4
Netapp ≫ Active Iq Unified Manager SwPlatform windows Version >= 7.3
Netapp ≫ Active Iq Unified Manager SwPlatform vmware_vsphere Version >= 9.5
Netapp ≫ Cloud Backup Version -
Netapp ≫ E-series Santricity Management Version - SwPlatform vmware_sra
Netapp ≫ E-series Santricity Management Version - SwPlatform vmware_vasa
Netapp ≫ E-series Santricity Management Version - SwPlatform vmware_vcenter
Netapp ≫ E-series Santricity Os Controller Version >= 11.0.0 <= 11.70.1
Netapp ≫ E-series Santricity Web Services Version - SwPlatform web_services_proxy
Netapp ≫ Oncommand Balance Version -
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Performance Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Oncommand Shift Version -
Netapp ≫ Oncommand Unified Manager SwPlatform vsphere Version <= 7.1
Netapp ≫ Oncommand Unified Manager SwPlatform windows Version <= 7.1
Netapp ≫ Oncommand Unified Manager Version - SwPlatform 7-mode
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Netapp ≫ Solidfire Version -
Netapp ≫ Storage Replication Adapter For Clustered Data Ontap Version - SwPlatform vmware_vsphere
Netapp ≫ Symantec Netbackup Version -
Netapp ≫ Virtual Storage Console Version - SwPlatform vmware_vsphere
Netapp ≫ Hci Storage Node Version -
Nodejs ≫ Node.Js SwEdition - Version >= 4.0.0 <= 4.1.2
Nodejs ≫ Node.Js SwEdition lts Version >= 4.2.0 < 4.8.2
Nodejs ≫ Node.Js SwEdition - Version >= 6.0.0 <= 6.8.1
Nodejs ≫ Node.Js SwEdition lts Version >= 6.9.0 < 6.10.2
Nodejs ≫ Node.Js SwEdition - Version >= 7.0.0 < 7.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.55% 0.938
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
https://www.oracle.com/security-alerts/cpujul2020.html
http://www.securitytracker.com/id/1039427
http://www.securitytracker.com/id/1039596
https://security.netapp.com/advisory/ntap-20171019-0001/
http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html
http://www.openwall.com/lists/oss-security/2016/12/05/21
http://www.securityfocus.com/bid/95131
https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html
https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html
https://security.gentoo.org/glsa/201701-56
https://security.gentoo.org/glsa/202007-54
https://usn.ubuntu.com/4246-1/
https://usn.ubuntu.com/4292-1/
https://bugzilla.redhat.com/show_bug.cgi?id=1402346
https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecb
https://cert-portal.siemens.com/productcert/html/ssa-470355.html
https://access.redhat.com/errata/RHSA-2017:1220
https://access.redhat.com/errata/RHSA-2017:1221
https://access.redhat.com/errata/RHSA-2017:1222
https://access.redhat.com/errata/RHSA-2017:2999
https://access.redhat.com/errata/RHSA-2017:3046
https://access.redhat.com/errata/RHSA-2017:3047
https://access.redhat.com/errata/RHSA-2017:3453
https://support.apple.com/HT208112
https://support.apple.com/HT208113
https://support.apple.com/HT208115
https://support.apple.com/HT208144
https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib
https://wiki.mozilla.org/images/0/09/Zlib-report.pdf