inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apple
Subscribe
|
|
|
Boost
Subscribe
|
Boost
Subscribe
|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Nodejs
Subscribe
|
Node.js
Subscribe
|
|
Opensuse
Subscribe
|
|
|
Oracle
Subscribe
|
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Network Satellite
Subscribe
Openshift
Subscribe
Rhel Aus
Subscribe
Rhel Els
Subscribe
Rhel Extras
Subscribe
Rhel Extras Oracle Java
Subscribe
Satellite
Subscribe
|
|
Zlib
Subscribe
|
Zlib
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1725-1 | rsync security update |
Debian DLA |
DLA-2085-1 | zlib security update |
EUVD |
EUVD-2016-10640 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
Ubuntu USN |
USN-4246-1 | zlib vulnerabilities |
Ubuntu USN |
USN-4292-1 | rsync vulnerabilities |
Ubuntu USN |
USN-6736-1 | klibc vulnerabilities |
Ubuntu USN |
USN-6736-2 | klibc vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Aus
|
|
| CPEs | cpe:/o:redhat:rhel_aus:8.4 | |
| Vendors & Products |
Redhat rhel Aus
|
Sat, 14 Jun 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | zlib: Out-of-bounds pointer arithmetic in inftrees.c | zlib: Out-of-bound pointer arithmetic in inftrees.c |
| Weaknesses | CWE-125 |
Fri, 06 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
|
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 cpe:/a:redhat:openshift:4.18::el9 |
|
| Vendors & Products |
Redhat openshift
|
Tue, 03 Jun 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux
|
|
| CPEs | cpe:/o:redhat:enterprise_linux:8 | |
| Vendors & Products |
Redhat enterprise Linux
|
Fri, 30 May 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Els
|
|
| CPEs | cpe:/o:redhat:rhel_els:7 | |
| Vendors & Products |
Redhat rhel Els
|
Fri, 28 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Boost
Boost boost |
|
| CPEs | cpe:2.3:a:boost:boost:*:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:* |
|
| Vendors & Products |
Boost
Boost boost |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-08-06T02:59:03.590Z
Reserved: 2016-12-05T00:00:00
Link: CVE-2016-9840
No data.
Status : Deferred
Published: 2017-05-23T04:29:01.667
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-9840
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN