PT-2016-3192 · Zlib+5 · Zlib+5

Published

2016-09-22

·

Updated

2024-08-28

·

CVE-2016-9842

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zlib versions 1.2.8
Description The issue is related to an error in handling negative numbers in the inflateMark function of the zlib library. This could allow a remote attacker to cause unspecified impact, potentially leading to disruption of confidentiality, integrity, and availability of protected information. The vulnerability might be exploited by vectors involving left shifts of negative integers, and it could also lead to a denial of service via a big-endian out-of-bounds pointer.
Recommendations For zlib version 1.2.8, consider disabling the inflateMark function as a temporary workaround until a patch is available. Restrict access to the zlib library to minimize the risk of exploitation. Avoid using the zlib library to process specially crafted documents until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1439
ALT-PU-2018-2668
ALT-PU-2018-2752
AZL-44631
AZL-45183
BDU:2017-02383
CVE-2016-9842
DLA-1725-1
DLA-2085-1
MGASA-2020-0108
OESA-2023-1433
OPENSUSE-SU-2017_2998-1
OPENSUSE-SU-2018_0042-1
PSF-2017-4
RHSA-2017:1220
RHSA-2017:1221
RHSA-2017:1222
RHSA-2017:2999
RHSA-2017:3046
RHSA-2017:3047
RHSA-2017:3453
RHSA-2017_1220
RHSA-2017_1221
RHSA-2017_1222
RHSA-2017_2999
RHSA-2017_3046
RHSA-2017_3047
SUSE-SU-2016:3209-1
SUSE-SU-2017:0003-1
SUSE-SU-2017:0004-1
SUSE-SU-2017:1384-1
SUSE-SU-2017:1385-1
SUSE-SU-2017:1386-1
SUSE-SU-2017:1387-1
SUSE-SU-2017:1389-1
SUSE-SU-2017:1444-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017:2989-1
SUSE-SU-2018:0005-1
SUSE-SU-2018:1815-1
USN-4246-1
USN-4292-1

Affected Products

Alt Linux
Ibm Aix
Red Hat
Suse
Ubuntu
Zlib