CVE Vulnerabilities

CVE-2016-9842

Published: May 23, 2017 | Modified: Aug 28, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
8.8 LOW
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Affected Software

Name Vendor Start Version End Version
Zlib Zlib 1.2.3.4 (including) 1.2.9 (excluding)
Oracle Java for Red Hat Enterprise Linux 6 RedHat java-1.8.0-oracle-1:1.8.0.151-1jpp.1.el6 *
Oracle Java for Red Hat Enterprise Linux 6 RedHat java-1.7.0-oracle-1:1.7.0.161-1jpp.3.el6 *
Oracle Java for Red Hat Enterprise Linux 6 RedHat java-1.6.0-sun-1:1.6.0.171-1jpp.4.el6 *
Oracle Java for Red Hat Enterprise Linux 7 RedHat java-1.8.0-oracle-1:1.8.0.151-1jpp.5.el7 *
Oracle Java for Red Hat Enterprise Linux 7 RedHat java-1.7.0-oracle-1:1.7.0.161-1jpp.4.el7 *
Oracle Java for Red Hat Enterprise Linux 7 RedHat java-1.6.0-sun-1:1.6.0.171-1jpp.4.el7 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.8.0-ibm-1:1.8.0.4.5-1jpp.1.el6_9 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.7.1-ibm-1:1.7.1.4.5-1jpp.2.el6_9 *
Red Hat Enterprise Linux 6 Supplementary RedHat java-1.6.0-ibm-1:1.6.0.16.45-1jpp.1.el6_9 *
Red Hat Enterprise Linux 7 Supplementary RedHat java-1.8.0-ibm-1:1.8.0.4.5-1jpp.1.el7_3 *
Red Hat Enterprise Linux 7 Supplementary RedHat java-1.7.1-ibm-1:1.7.1.4.5-1jpp.1.el7_3 *
Red Hat Satellite 5.8 RedHat java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 *
Red Hat Satellite 5.8 ELS RedHat java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 *
Rsync Ubuntu bionic *
Rsync Ubuntu devel *
Rsync Ubuntu disco *
Rsync Ubuntu eoan *
Rsync Ubuntu focal *
Rsync Ubuntu groovy *
Rsync Ubuntu hirsute *
Rsync Ubuntu impish *
Rsync Ubuntu jammy *
Rsync Ubuntu kinetic *
Rsync Ubuntu lunar *
Rsync Ubuntu mantic *
Rsync Ubuntu noble *
Rsync Ubuntu oracular *
Rsync Ubuntu xenial *
Zlib Ubuntu esm-infra-legacy/trusty *
Zlib Ubuntu precise *
Zlib Ubuntu precise/esm *
Zlib Ubuntu trusty *
Zlib Ubuntu trusty/esm *
Zlib Ubuntu upstream *
Zlib Ubuntu vivid/stable-phone-overlay *
Zlib Ubuntu vivid/ubuntu-core *
Zlib Ubuntu xenial *
Zlib Ubuntu yakkety *
Zlib Ubuntu zesty *

References