CVE-2016-9840High· 8.8▾ Twilightinftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.8%
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
boost < 1.78.0zlib >= 1.2.0.6, < 1.2.9leap = 42.1leap = 42.2opensuse = 13.2debian_linux = 8.0ubuntu_linux = 16.04ubuntu_linux = 18.04database_server = 18cjdk = 1.6.0jdk = 1.7.0jdk = 1.8.0jre = 1.6.0jre = 1.7.0jre = 1.8.0mysql >= 5.5.0, <= 5.5.61mysql >= 5.6.0, <= 5.6.41mysql >= 5.7.0, <= 5.7.23mysql >= 8.0.0, <= 8.0.12satellite = 5.8enterprise_linux_desktop = 6.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.4enterprise_linux_eus = 7.5enterprise_linux_server = 6.0enterprise_linux_server = 7.0enterprise_linux_workstation = 6.0enterprise_linux_workstation = 7.0iphone_os < 11mac_os_x >= 10.0.0, < 10.13.0tvos < 11.0watchos < 4node.js >= 4.0.0, <= 4.1.2node.js >= 4.2.0, < 4.8.2node.js >= 6.0.0, <= 6.8.1node.js >= 6.9.0, < 6.10.2node.js >= 7.0.0, < 7.6.0Upgrade past the affected range:
boost 1.78.0zlib 1.2.9iphone_os 11mac_os_x 10.13.0tvos 11.0watchos 4node.js 7.6.0