PT-2017-2599 · Zlib+8 · Zlib+8

Published

2016-12-21

·

Updated

2026-03-10

·

CVE-2016-9843

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zlib versions 1.2.8 and earlier MySQL Server versions 5.5.61 and earlier, 5.6.41 and earlier, 5.7.23 and earlier, 8.0.12 and earlier
Description The issue is related to errors in handling numbers in the crc32 big function of the zlib library, which may allow attackers to impact the confidentiality, integrity, and availability of protected information during big-endian CRC calculation. This can be exploited by a remote attacker to cause a denial of service, potentially leading to a hang or crash of the MySQL Server. The vulnerability can be triggered by persuading a victim to open a specially crafted document.
Recommendations For zlib version 1.2.8 and earlier, consider disabling the crc32 big function until a patch is available. For MySQL Server versions 5.5.61 and earlier, 5.6.41 and earlier, 5.7.23 and earlier, 8.0.12 and earlier, update to a version that includes the fix for the zlib vulnerability. As a temporary workaround, restrict access to the zlib library to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1439
ALT-PU-2018-2668
ALT-PU-2018-2720
ALT-PU-2018-2752
AZL-44352
AZL-45366
BDU:2017-01815
CVE-2016-9843
DLA-1725-1
DLA-2085-1
MGASA-2018-0469
MGASA-2020-0108
OESA-2023-1433
OPENSUSE-SU-2017_2998-1
OPENSUSE-SU-2018_0042-1
OPENSUSE-SU-2018_3478-1
OPENSUSE-SU-2019:0327-1
OPENSUSE-SU-2019_0327-1
OPENSUSE-SU-2024:10283-1
OPENSUSE-SU-2024:10876-1
OPENSUSE-SU-2025:14656-1
PSF-2017-5
RHSA-2017:1220
RHSA-2017:1221
RHSA-2017:1222
RHSA-2017:2999
RHSA-2017:3046
RHSA-2017:3047
RHSA-2017:3453
RHSA-2017_1220
RHSA-2017_1221
RHSA-2017_1222
RHSA-2017_2999
RHSA-2017_3046
RHSA-2017_3047
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2016:3209-1
SUSE-SU-2017:0003-1
SUSE-SU-2017:0004-1
SUSE-SU-2017:1384-1
SUSE-SU-2017:1385-1
SUSE-SU-2017:1386-1
SUSE-SU-2017:1387-1
SUSE-SU-2017:1389-1
SUSE-SU-2017:1444-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017:2989-1
SUSE-SU-2018:0005-1
SUSE-SU-2018:1815-1
SUSE-SU-2018:3542-1
SUSE-SU-2018:3972-1
SUSE-SU-2018:4211-1
SUSE-SU-2018_3542-1
SUSE-SU-2018_3972-1
SUSE-SU-2018_4211-1
SUSE-SU-2019:0119-1
SUSE-SU-2019:0555-1
SUSE-SU-2019:0628-1
SUSE-SU-2019:1441-1
SUSE-SU-2019:2048-1
SUSE-SU-2019_0119-1
SUSE-SU-2019_0555-1
SUSE-SU-2019_2048-1
USN-4246-1
USN-4292-1
USN-7959-1

Affected Products

Alt Linux
Ibm Aix
Linuxmint
Mariadb Server
Mysql Server
Red Hat
Suse
Ubuntu
Zlib