Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9840

Опубликовано: 22 сент. 2016
Источник: redhat
CVSS3: 8.8
CVSS2: 4.3
EPSS Низкий

Описание

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

A vulnerability was discovered in the inftrees.c file of zlib. Pointer arithmetic operations violate the C standard by subtracting an offset from an array pointer before its allocated memory, leading to undefined behavior.

Отчет

While this undefined behavior does not currently manifest as an exploitable issue on Red Hat Enterprise Linux systems using GCC compilers, it could become problematic with future compiler implementations. This flaw affects various Java packages in Red Hat Enterprise Linux 6 and 7, but native zlib packages in Red Hat Enterprise Linux are not impacted due to the specific compiler implementation used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncNot affected
Red Hat Enterprise Linux 5zlibNot affected
Red Hat Enterprise Linux 6zlibNot affected
Red Hat Enterprise Linux 9rsyncNot affected
Red Hat JBoss Enterprise Application Platform 5zlibNot affected
Red Hat JBoss Enterprise Application Platform 6zlibNot affected
Red Hat JBoss Enterprise Web Server 1zlibNot affected
Red Hat JBoss Enterprise Web Server 2zlibNot affected
Red Hat JBoss Enterprise Web Server 3zlibNot affected
Oracle Java for Red Hat Enterprise Linux 6java-1.8.0-oracleFixedRHSA-2017:299923.10.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1402345zlib: Out-of-bound pointer arithmetic in inftrees.c

EPSS

Процентиль: 90%
0.0554
Низкий

8.8 High

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS3: 8.8
nvd
около 8 лет назад

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS3: 8.8
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 8.8
debian
около 8 лет назад

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to ha ...

suse-cvrf
10 дней назад

Security update for boost

EPSS

Процентиль: 90%
0.0554
Низкий

8.8 High

CVSS3

4.3 Medium

CVSS2