CVE-2016-9843

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
microfocusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
zlibzlib
1.2.0 ≤
𝑥
< 1.2.9
opensuseleap
42.1
opensuseleap
42.2
opensuseopensuse
13.2
debiandebian_linux
8.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
oraclejdk
1.6.0
oraclejdk
1.7.0
oraclejdk
1.8.0
oraclejre
1.6.0
oraclejre
1.7.0
oraclejre
1.8.0
oraclemysql
5.5.0 ≤
𝑥
≤ 5.5.61
oraclemysql
5.6.0 ≤
𝑥
≤ 5.6.41
oraclemysql
5.7.0 ≤
𝑥
≤ 5.7.23
oraclemysql
8.0.0 ≤
𝑥
≤ 8.0.12
redhatsatellite
5.8
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
appleiphone_os
𝑥
< 11
applemac_os_x
10.0.0 ≤
𝑥
< 10.13.0
appletvos
𝑥
< 11.0
applewatchos
𝑥
< 4
netappactive_iq_unified_manager
7.3 ≤
netappactive_iq_unified_manager
9.5 ≤
netapponcommand_insight
-
netapponcommand_workflow_automation
-
netappsnapcenter
-
mariadbmariadb
5.5.0 ≤
𝑥
< 5.5.62
mariadbmariadb
10.0.0 ≤
𝑥
< 10.0.37
mariadbmariadb
10.1.0 ≤
𝑥
< 10.1.37
mariadbmariadb
10.2.0 ≤
𝑥
< 10.2.19
mariadbmariadb
10.3.0 ≤
𝑥
< 10.3.11
nodejsnode.js
4.0.0 ≤
𝑥
≤ 4.1.2
nodejsnode.js
4.2.0 ≤
𝑥
< 4.8.2
nodejsnode.js
6.0.0 ≤
𝑥
≤ 6.8.1
nodejsnode.js
6.9.0 ≤
𝑥
< 6.10.2
nodejsnode.js
7.0.0 ≤
𝑥
< 7.6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rsync
bullseye
3.2.3-4+deb11u1
fixed
wheezy
no-dsa
bookworm
3.2.7-1
fixed
sid
3.3.0-1
fixed
trixie
3.3.0-1
fixed
zlib
bullseye (security)
1:1.2.11.dfsg-2+deb11u2
fixed
bullseye
1:1.2.11.dfsg-2+deb11u2
fixed
wheezy
no-dsa
bookworm
1:1.2.13.dfsg-1
fixed
sid
1:1.3.dfsg+really1.3.1-1
fixed
trixie
1:1.3.dfsg+really1.3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
klibc
noble
needs-triage
mantic
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected
rsync
noble
Fixed 3.1.3-6
released
mantic
Fixed 3.1.3-6
released
lunar
Fixed 3.1.3-6
released
kinetic
Fixed 3.1.3-6
released
jammy
Fixed 3.1.3-6
released
impish
Fixed 3.1.3-6
released
hirsute
Fixed 3.1.3-6
released
groovy
Fixed 3.1.3-6
released
focal
Fixed 3.1.3-6
released
eoan
Fixed 3.1.3-6
released
disco
Fixed 3.1.3-6
released
bionic
Fixed 3.1.2-2.1ubuntu1.1
released
xenial
Fixed 3.1.1-3ubuntu1.3
released
trusty
not-affected
zlib
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
ignored
yakkety
ignored
xenial
Fixed 1:1.2.8.dfsg-2ubuntu4.3
released
trusty
needed
precise
ignored
References