CVE-2016-9841
9.8
CRITICAL · CVSS 3.1 · EPSS 7.6% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.55% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-05-23 |
| Last modified | 2026-07-14 |
Affected (39)
| Vendor | Product |
|---|---|
| apple | iphone os |
| apple | mac os x |
| apple | tvos |
| apple | watchos |
| canonical | ubuntu linux |
| debian | debian linux |
| netapp | active iq unified manager |
| netapp | cloud backup |
| netapp | e-series santricity management |
| netapp | e-series santricity os controller |
| netapp | e-series santricity storage manager |
| netapp | e-series santricity web services |
| netapp | hci storage node |
| netapp | oncommand balance |
| netapp | oncommand insight |
| netapp | oncommand performance manager |
| netapp | oncommand shift |
| netapp | oncommand unified manager |
| netapp | oncommand workflow automation |
| netapp | snapmanager |
| netapp | solidfire |
| netapp | steelstore cloud integrated storage |
| netapp | storage replication adapter for clustered data ontap |
| netapp | symantec netbackup |
| netapp | vasa provider for clustered data ontap |
| netapp | virtual storage console |
| nodejs | node.js |
| opensuse | leap |
| opensuse | opensuse |
| oracle | database server |
| oracle | jdk |
| oracle | jre |
| oracle | mysql |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| redhat | satellite |
| zlib | zlib |
References
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html
- http://www.openwall.com/lists/oss-security/2016/12/05/21
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/95131
- http://www.securitytracker.com/id/1039427
- http://www.securitytracker.com/id/1039596
- https://access.redhat.com/errata/RHSA-2017:1220
- https://access.redhat.com/errata/RHSA-2017:1221
- https://access.redhat.com/errata/RHSA-2017:1222
- https://access.redhat.com/errata/RHSA-2017:2999
- https://access.redhat.com/errata/RHSA-2017:3046
- https://access.redhat.com/errata/RHSA-2017:3047
- https://access.redhat.com/errata/RHSA-2017:3453
- https://bugzilla.redhat.com/show_bug.cgi?id=1402346
- https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecb
- https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html
→ the Explorer · watch your stack · NVD