Description
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1725-1 | rsync security update |
Debian DLA |
DLA-2085-1 | zlib security update |
EUVD |
EUVD-2016-10640 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
Ubuntu USN |
USN-4246-1 | zlib vulnerabilities |
Ubuntu USN |
USN-4292-1 | rsync vulnerabilities |
Ubuntu USN |
USN-6736-1 | klibc vulnerabilities |
Ubuntu USN |
USN-6736-2 | klibc vulnerabilities |
References
History
Tue, 08 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Aus
|
|
| CPEs | cpe:/o:redhat:rhel_aus:8.4 | |
| Vendors & Products |
Redhat rhel Aus
|
Sat, 14 Jun 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | zlib: Out-of-bounds pointer arithmetic in inftrees.c | zlib: Out-of-bound pointer arithmetic in inftrees.c |
| Weaknesses | CWE-125 |
Fri, 06 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
|
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 cpe:/a:redhat:openshift:4.18::el9 |
|
| Vendors & Products |
Redhat openshift
|
Tue, 03 Jun 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux
|
|
| CPEs | cpe:/o:redhat:enterprise_linux:8 | |
| Vendors & Products |
Redhat enterprise Linux
|
Fri, 30 May 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Els
|
|
| CPEs | cpe:/o:redhat:rhel_els:7 | |
| Vendors & Products |
Redhat rhel Els
|
Fri, 28 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boost
Boost boost |
|
| CPEs | cpe:2.3:a:boost:boost:*:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:* |
|
| Vendors & Products |
Boost
Boost boost |
Subscriptions
Apple
Subscribe
Iphone Os
Subscribe
Mac Os X
Subscribe
Tvos
Subscribe
Watchos
Subscribe
Boost
Subscribe
Boost
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Nodejs
Subscribe
Node.js
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Opensuse
Subscribe
Oracle
Subscribe
Database Server
Subscribe
Jdk
Subscribe
Jre
Subscribe
Mysql
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Network Satellite
Subscribe
Openshift
Subscribe
Rhel Aus
Subscribe
Rhel Els
Subscribe
Rhel Extras
Subscribe
Rhel Extras Oracle Java
Subscribe
Satellite
Subscribe
Zlib
Subscribe
Zlib
Subscribe
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2026-07-14T11:44:48.582Z
Reserved: 2016-12-05T00:00:00.000Z
Link: CVE-2016-9840
No data.
Status : Modified
Published: 2017-05-23T04:29:01.667
Modified: 2026-07-14T12:16:45.520
Link: CVE-2016-9840
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-125
Out-of-bounds Read
- NVD-CWE-noinfo
Debian DLA
EUVD
Ubuntu USN