8.8

CVE-2016-9842

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zlib ≫ Zlib Version >= 1.2.3.4 < 1.2.9
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Leap Version 42.2
Opensuse ≫ Opensuse Version 13.2
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition esm
Oracle ≫ Database Server Version 18c
Oracle ≫ Jdk Version 1.6.0 Update update161
Oracle ≫ Jdk Version 1.7.0 Update update151
Oracle ≫ Jdk Version 1.8.0 Update update144
Oracle ≫ Jre Version 1.6.0 Update update161
Oracle ≫ Jre Version 1.7.0 Update update151
Oracle ≫ Jre Version 1.8.0 Update update144
Oracle ≫ Mysql Version >= 5.5.0 <= 5.5.61
Oracle ≫ Mysql Version >= 5.6.0 <= 5.6.41
Oracle ≫ Mysql Version >= 5.7.0 <= 5.7.23
Oracle ≫ Mysql Version >= 8.0.0 <= 8.0.12
Redhat ≫ Satellite Version 5.8
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Apple ≫ iPhone OS Version < 11
Apple ≫ macOS X Version >= 10.0.0 < 10.13.0
Apple ≫ tvOS Version < 11.0
Apple ≫ watchOS Version < 4
Nodejs ≫ Node.Js SwEdition - Version >= 4.0.0 <= 4.1.2
Nodejs ≫ Node.Js SwEdition lts Version >= 4.2.0 < 4.8.2
Nodejs ≫ Node.Js SwEdition - Version >= 6.0.0 <= 6.8.1
Nodejs ≫ Node.Js SwEdition lts Version >= 6.9.0 < 6.10.2
Nodejs ≫ Node.Js SwEdition - Version >= 7.0.0 < 7.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.2% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-1335 Incorrect Bitwise Shift of Integer

An integer value is specified to be shifted by a negative amount or an amount greater than or equal to the number of bits contained in the value causing an unexpected or indeterminate result.

http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
http://www.securitytracker.com/id/1039427
Third Party Advisory
Broken Link
VDB Entry
http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html
Broken Link
http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html
Broken Link
http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html
Broken Link
http://www.openwall.com/lists/oss-security/2016/12/05/21
Patch
Mailing List
http://www.securityfocus.com/bid/95131
Third Party Advisory
Broken Link
VDB Entry
https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/201701-56
Third Party Advisory
https://security.gentoo.org/glsa/202007-54
Third Party Advisory
https://usn.ubuntu.com/4246-1/
Third Party Advisory
https://usn.ubuntu.com/4292-1/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1402348
Patch
Issue Tracking
https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958
Patch
https://cert-portal.siemens.com/productcert/html/ssa-470355.html
https://access.redhat.com/errata/RHSA-2017:1220
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1221
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1222
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2999
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3046
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3047
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3453
Third Party Advisory
https://support.apple.com/HT208112
Third Party Advisory
https://support.apple.com/HT208113
Third Party Advisory
https://support.apple.com/HT208115
Third Party Advisory
https://support.apple.com/HT208144
Third Party Advisory
https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib
Third Party Advisory
https://wiki.mozilla.org/images/0/09/Zlib-report.pdf
Third Party Advisory