← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-9843

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:5.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
zlib zlib all
opensuse leap 42.1, 42.2
opensuse opensuse 13.2
debian debian_linux 8.0
canonical ubuntu_linux 16.04, 18.04
oracle database_server 18c
oracle jdk 1.6.0, 1.7.0, 1.8.0
oracle jre 1.6.0, 1.7.0, 1.8.0
oracle mysql all
redhat satellite 5.8
redhat enterprise_linux_desktop 6.0, 7.0
redhat enterprise_linux_eus 7.4, 7.5
redhat enterprise_linux_server 6.0, 7.0
redhat enterprise_linux_workstation 6.0, 7.0
apple iphone_os all
apple mac_os_x all
apple tvos all
apple watchos all
netapp active_iq_unified_manager all
netapp oncommand_insight all
netapp oncommand_workflow_automation all
netapp snapcenter all
mariadb mariadb all
nodejs node.js all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.950%

Identity & Timeline

StatusPUBLISHED
Assigning Authoritymicrofocus
Reserved2016-12-05T00:00:00
Published2017-05-23T03:56:00
Patch Date2016-09-30
Last Updated2024-08-06T02:59:03

LINK COPIED TO CLIPBOARD