Back

HIGH

zlib: Out-of-bound pointer arithmetic in inftrees.c

Published May 23, 2017

Description

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Affected products

Remediation

Red Hat statement

While this undefined behavior does not currently manifest as an exploitable issue on Red Hat Enterprise Linux systems using GCC compilers, it could become problematic with future compiler implementations. This flaw affects various Java packages in Red Hat Enterprise Linux 6 and 7, but native zlib packages in Red Hat Enterprise Linux are not impacted due to the specific compiler implementation used.

Metrics

References (35)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published May 23, 2017
Updated Jul 14, 2026
Reserved Dec 5, 2016
NVD
Status Modified
Modified Jul 14, 2026
Red Hat
Severity Low
Public date Sep 22, 2016