zlib: Big-endian out-of-bounds pointer
Published May 23, 2017
9.8
CRITICALCVSS 3.1
EPSS 5.77%
Description
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
Affected products
No data.
Configuration 3
- 8.0
Configuration 4
- 16.04
- 18.04
Configuration 5
- 18c
- 1.6.0
- 1.7.0
- 1.8.0
- 1.6.0
- 1.7.0
- 1.8.0
- ≥ 5.5.0 · ≤ 5.5.61
- ≥ 5.6.0 · ≤ 5.6.41
- ≥ 5.7.0 · ≤ 5.7.23
- ≥ 8.0.0 · ≤ 8.0.12
Configuration 6
- 5.8
- 6.0
- 7.0
- 7.4
- 7.5
- 6.0
- 7.0
- 6.0
- 7.0
Configuration 7
Configuration 8
- ≥ 7.3
- ≥ 9.5
- n/a
- n/a
- n/a
Configuration 9
No data.
Oracle Java for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.171-1jpp.4.el6
Fixed · RHSA-2017:3047
Oracle Java for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.161-1jpp.3.el6
Fixed · RHSA-2017:3046
Oracle Java for Red Hat Enterprise Linux 6
java-1.8.0-oracle-1:1.8.0.151-1jpp.1.el6
Fixed · RHSA-2017:2999
Oracle Java for Red Hat Enterprise Linux 7
java-1.6.0-sun-1:1.6.0.171-1jpp.4.el7
Fixed · RHSA-2017:3047
Oracle Java for Red Hat Enterprise Linux 7
java-1.7.0-oracle-1:1.7.0.161-1jpp.4.el7
Fixed · RHSA-2017:3046
Oracle Java for Red Hat Enterprise Linux 7
java-1.8.0-oracle-1:1.8.0.151-1jpp.5.el7
Fixed · RHSA-2017:2999
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.16.45-1jpp.1.el6_9
Fixed · RHSA-2017:1222
Red Hat Enterprise Linux 6 Supplementary
java-1.7.1-ibm-1:1.7.1.4.5-1jpp.2.el6_9
Fixed · RHSA-2017:1221
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.4.5-1jpp.1.el6_9
Fixed · RHSA-2017:1220
Red Hat Enterprise Linux 7 Supplementary
java-1.7.1-ibm-1:1.7.1.4.5-1jpp.1.el7_3
Fixed · RHSA-2017:1221
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.4.5-1jpp.1.el7_3
Fixed · RHSA-2017:1220
Red Hat Satellite 5.8
java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9
Fixed · RHSA-2017:3453
Red Hat Satellite 5.8 ELS
java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9
Fixed · RHSA-2017:3453
Red Hat Enterprise Linux 5
zlib
Not affected
Red Hat Enterprise Linux 6
zlib
Not affected
Red Hat Enterprise Linux 7
zlib
Not affected
Red Hat JBoss Enterprise Application Platform 5
zlib
Not affected
Red Hat JBoss Enterprise Application Platform 6
zlib
Not affected
Red Hat JBoss Enterprise Web Server 1
zlib
Not affected
Red Hat JBoss Enterprise Web Server 2
zlib
Not affected
Red Hat JBoss Enterprise Web Server 3
zlib
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.171-1jpp.4.el6 | Fixed | RHSA-2017:3047 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.161-1jpp.3.el6 | Fixed | RHSA-2017:3046 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.8.0-oracle-1:1.8.0.151-1jpp.1.el6 | Fixed | RHSA-2017:2999 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.6.0-sun-1:1.6.0.171-1jpp.4.el7 | Fixed | RHSA-2017:3047 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.7.0-oracle-1:1.7.0.161-1jpp.4.el7 | Fixed | RHSA-2017:3046 |
| Oracle Java for Red Hat Enterprise Linux 7 | java-1.8.0-oracle-1:1.8.0.151-1jpp.5.el7 | Fixed | RHSA-2017:2999 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.16.45-1jpp.1.el6_9 | Fixed | RHSA-2017:1222 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm-1:1.7.1.4.5-1jpp.2.el6_9 | Fixed | RHSA-2017:1221 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.4.5-1jpp.1.el6_9 | Fixed | RHSA-2017:1220 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm-1:1.7.1.4.5-1jpp.1.el7_3 | Fixed | RHSA-2017:1221 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.4.5-1jpp.1.el7_3 | Fixed | RHSA-2017:1220 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 | Fixed | RHSA-2017:3453 |
| Red Hat Satellite 5.8 ELS | java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 | Fixed | RHSA-2017:3453 |
| Red Hat Enterprise Linux 5 | zlib | Not affected | n/a |
| Red Hat Enterprise Linux 6 | zlib | Not affected | n/a |
| Red Hat Enterprise Linux 7 | zlib | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | zlib | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | zlib | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | zlib | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | zlib | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | zlib | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.77% (0.05766) | 92.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.00% (0.05999) | 92.36th | v5 (v2026.06.15) |
| Jun 14, 2026 | 17.67% (0.17674) | 95.28th | v4 (v2025.03.14) |
| Jun 6, 2026 | 13.50% (0.13502) | 94.36th | v4 (v2025.03.14) |
| Jun 5, 2026 | 16.96% (0.16958) | 95.10th | v4 (v2025.03.14) |
| May 28, 2026 | 15.07% (0.15071) | 94.68th | v4 (v2025.03.14) |
| May 23, 2026 | 11.80% (0.11796) | 93.80th | v4 (v2025.03.14) |
| Mar 15, 2026 | 15.07% (0.15071) | 94.47th | v4 (v2025.03.14) |
| Jan 12, 2026 | 7.98% (0.07983) | 91.80th | v4 (v2025.03.14) |
| Dec 28, 2025 | 6.98% (0.06977) | 91.13th | v4 (v2025.03.14) |
| Dec 27, 2025 | 5.00% (0.05001) | 89.41th | v4 (v2025.03.14) |
| Nov 19, 2025 | 6.98% (0.06977) | 90.55th | v4 (v2025.03.14) |
| Oct 28, 2025 | 9.18% (0.09182) | 92.32th | v4 (v2025.03.14) |
| Oct 27, 2025 | 5.00% (0.05001) | 89.24th | v4 (v2025.03.14) |
| Oct 1, 2025 | 9.18% (0.09182) | 92.43th | v4 (v2025.03.14) |
| Jul 30, 2025 | 5.00% (0.05001) | 89.29th | v4 (v2025.03.14) |
| Mar 30, 2025 | 9.23% (0.09233) | 91.95th | v4 (v2025.03.14) |
| Mar 29, 2025 | 33.77% (0.33772) | 95.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 9.23% (0.09233) | 92.11th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.38% (0.01381) | 86.88th | v3 (v2023.03.01) |
| Dec 24, 2023 | 1.38% (0.01381) | 84.86th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.41% (0.01413) | 84.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.12% (0.00117) | 43.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
No CWE recorded.
References (37)
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html vendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2016/12/05/21 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/95131 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1039427 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id/1041888 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/errata/RHSA-2017:1220 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1221 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:1222 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2999 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:3046 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:3047 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:3453 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2016-9843 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1402351 x_refsource_CONFIRMIssue Tracking
- https://docs.google.com/document/d/10i1KZS5so8xDqH2rplRa2xet0tyTvvJlLbQQmZIUIKE/edit#heading=h.t13tvnx4loq7
- https://github.com/madler/zlib/commit/d1d577490c15a0c6862473d7576352a9f18ef811 x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2016-9843
- https://security.gentoo.org/glsa/201701-56 vendor-advisoryx_refsource_GENTOO
- https://security.gentoo.org/glsa/202007-54 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20181018-0002/ x_refsource_CONFIRM
- https://support.apple.com/HT208112 x_refsource_CONFIRM
- https://support.apple.com/HT208113 x_refsource_CONFIRM
- https://support.apple.com/HT208115 x_refsource_CONFIRM
- https://support.apple.com/HT208144 x_refsource_CONFIRM
- https://usn.ubuntu.com/4246-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4292-1/ vendor-advisoryx_refsource_UBUNTU
- https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib x_refsource_MISC
- https://wiki.mozilla.org/images/0/09/Zlib-report.pdf x_refsource_MISC
- https://www.cve.org/CVERecord?id=CVE-2016-9843
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISC
Change history (0)
No recorded changes yet.