PT-2016-3191 · Zlib+9 · Zlib+9

Publicado

2016-09-22

·

Atualizado

2025-12-03

·

CVE-2016-9840

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zlib version 1.2.8
Description The issue is caused by improper pointer arithmetic in the inftrees.c component of the zlib library. This could allow a remote attacker to exploit the vulnerability, potentially leading to unspecified impact, including disruption of confidentiality, integrity, and availability of protected information. The vulnerability may be exploited by persuading a victim to open a specially crafted document, resulting in a denial of service.
Recommendations For zlib version 1.2.8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025:8395
ALT-PU-2017-1439
ALT-PU-2018-2668
ALT-PU-2018-2752
AZL-44046
AZL-45132
BDU:2017-02382
CESA-2025_8395
CVE-2016-9840
DLA-1725-1
DLA-2085-1
INFSA-2025_8395
MGASA-2020-0108
OESA-2023-1433
OPENSUSE-SU-2017_2998-1
OPENSUSE-SU-2018_0042-1
OPENSUSE-SU-2024:10876-1
OPENSUSE-SU-2024:11599-1
PSF-2017-2
RHSA-2017:1220
RHSA-2017:1221
RHSA-2017:1222
RHSA-2017:2999
RHSA-2017:3046
RHSA-2017:3047
RHSA-2017:3453
RHSA-2017_1220
RHSA-2017_1221
RHSA-2017_1222
RHSA-2017_2999
RHSA-2017_3046
RHSA-2017_3047
RHSA-2025:10541
RHSA-2025:11048
RHSA-2025:12013
RHSA-2025:13947
RHSA-2025:8314
RHSA-2025:8395
RHSA-2025_8395
SUSE-SU-2016:3209-1
SUSE-SU-2016_3209-1
SUSE-SU-2017:0003-1
SUSE-SU-2017:0004-1
SUSE-SU-2017:1384-1
SUSE-SU-2017:1385-1
SUSE-SU-2017:1386-1
SUSE-SU-2017:1387-1
SUSE-SU-2017:1389-1
SUSE-SU-2017:1444-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017:2989-1
SUSE-SU-2017_0003-1
SUSE-SU-2017_0004-1
SUSE-SU-2017_1384-1
SUSE-SU-2017_1385-1
SUSE-SU-2017_1386-1
SUSE-SU-2017_1387-1
SUSE-SU-2018:0005-1
SUSE-SU-2018:1815-1
SUSE-SU-2025:02536-1
SUSE-SU-2025_02536-1
USN-4246-1
USN-4292-1
USN-6736-1
USN-6736-2

Produtos afetados

Alt Linux
Almalinux
Centos
Ibm Aix
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Zlib