Description
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Apple / iphone_os11
- Apple / mac_os_x10.0.0 – 10.13.0
- Apple / tvOS11.0
- Apple / watchOS4
- Canonical / Ubuntu Linux16.04 – 16.04
- Canonical / Ubuntu Linux18.04 – 18.04
- debian / debian_linux8.0 – 8.0
- NETAPP / active_iq_unified_manager7.3 –
- NETAPP / active_iq_unified_manager9.5 –
- NETAPP / cloud_backup
- NETAPP / e-series_santricity_management
- NETAPP / e-series_santricity_management
- NETAPP / e-series_santricity_management
- NETAPP / e-series_santricity_os_controller11.0.0 – 11.70.1
- NETAPP / e-series_santricity_storage_manager
- NETAPP / e-series_santricity_web_services
- NETAPP / hci_storage_node
- NETAPP / oncommand_balance
- NETAPP / OnCommand Insight
- NETAPP / oncommand_performance_manager
- NETAPP / oncommand_shift
- NETAPP / OnCommand Unified Manager
- NETAPP / OnCommand Unified Manager7.1
- NETAPP / OnCommand Unified Manager7.1
- NETAPP / OnCommand Workflow Automation
- NETAPP / snapmanager
- NETAPP / snapmanager
- NETAPP / solidfire
- NETAPP / steelstore_cloud_integrated_storage
- NETAPP / storage_replication_adapter_for_clustered_data_ontap
- NETAPP / symantec_netbackup
- NETAPP / VASA Provider for Clustered Data ONTAP7.2 –
- NETAPP / virtual_storage_console
- nodejs / node.js4.0.0 – 4.1.2
- nodejs / node.js4.2.0 – 4.8.2
- openSUSE / Leap42.2 – 42.2
- openSUSE / Leap42.1 – 42.1
- openSUSE / opensuse13.2 – 13.2
- oracle / database_server18c – 18c
- oracle / jdk1.8.0 – 1.8.0
- oracle / jdk1.7.0 – 1.7.0
- oracle / jdk1.6.0 – 1.6.0
- oracle / jre1.6.0 – 1.6.0
- oracle / jre1.7.0 – 1.7.0
- oracle / jre1.8.0 – 1.8.0
- oracle / mysql5.5.0 – 5.5.61
- RedHat / enterprise_linux_desktop6.0 – 6.0
- RedHat / enterprise_linux_desktop7.0 – 7.0
- RedHat / enterprise_linux_eus7.4 – 7.4
- RedHat / enterprise_linux_eus7.5 – 7.5
- RedHat / enterprise_linux_server7.0 – 7.0
- RedHat / enterprise_linux_server6.0 – 6.0
- RedHat / enterprise_linux_workstation6.0 – 6.0
- RedHat / enterprise_linux_workstation7.0 – 7.0
- RedHat / satellite5.8 – 5.8
- zlib / zlib1.2.0 – 1.2.9
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:1221
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:1220
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3047
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2016/12/05/21
- MISChttp://www.securityfocus.com/bid/95131
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3046
- MAILING_LISThttp://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html
- MISChttp://www.securitytracker.com/id/1039596
- MISChttps://security.gentoo.org/glsa/201701-56
- MISChttp://www.securitytracker.com/id/1039427
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:1222
- MAILING_LISThttp://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3453
- MAILING_LISThttp://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:2999
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2019/03/msg00027.html
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4246-1/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2020/01/msg00030.html
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4292-1/
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2020.html
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- VENDOR_ADVISORYhttps://support.apple.com/HT208144
- MISChttps://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib
- VENDOR_ADVISORYhttps://support.apple.com/HT208113
- VENDOR_ADVISORYhttps://support.apple.com/HT208112
- VENDOR_ADVISORYhttps://support.apple.com/HT208115
- MISChttps://wiki.mozilla.org/images/0/09/Zlib-report.pdf
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=1402346
- PATCHhttps://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecb
- MISChttps://security.netapp.com/advisory/ntap-20171019-0001/
- MISChttps://security.gentoo.org/glsa/202007-54
Updated 17m ago · 8 sources