CVE-2016-9843

Source
https://cve.org/CVERecord?id=CVE-2016-9843
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9843.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-9843
Aliases
Downstream
Related
Published
2017-05-23T04:29:01.900Z
Modified
2026-07-17T20:58:34.969106067Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "fixed": "11"
                }
            ],
            "vendor_product": "apple:iphone_os",
            "source": "CPE_RANGE"
        },
        {
            "cpes": [
                "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "10.0.0"
                },
                {
                    "fixed": "10.13.0"
                }
            ],
            "vendor_product": "apple:mac_os_x",
            "source": "CPE_RANGE"
        },
        {
            "cpes": [
                "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "fixed": "11.0"
                }
            ],
            "vendor_product": "apple:tvos",
            "source": "CPE_RANGE"
        },
        {
            "cpes": [
                "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "fixed": "4"
                }
            ],
            "vendor_product": "apple:watchos",
            "source": "CPE_RANGE"
        },
        {
            "cpes": [
                "cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*",
                "cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "7.3"
                },
                {
                    "introduced": "9.5"
                }
            ],
            "vendor_product": "netapp:active_iq_unified_manager",
            "source": "CPE_RANGE"
        },
        {
            "cpes": [
                "cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*",
                "cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "4.0.0"
                },
                {
                    "last_affected": "4.1.2"
                },
                {
                    "introduced": "4.2.0"
                },
                {
                    "fixed": "4.8.2"
                },
                {
                    "introduced": "6.0.0"
                },
                {
                    "last_affected": "6.8.1"
                },
                {
                    "introduced": "6.9.0"
                },
                {
                    "fixed": "6.10.2"
                },
                {
                    "introduced": "7.0.0"
                },
                {
                    "fixed": "7.6.0"
                }
            ],
            "vendor_product": "nodejs:node.js",
            "source": "CPE_RANGE"
        },
        {
            "cpes": [
                "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
                "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "16.04"
                },
                {
                    "last_affected": "16.04"
                },
                {
                    "introduced": "18.04"
                },
                {
                    "last_affected": "18.04"
                }
            ],
            "vendor_product": "canonical:ubuntu_linux",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "8.0"
                },
                {
                    "last_affected": "8.0"
                }
            ],
            "vendor_product": "debian:debian_linux",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*",
                "cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "42.1"
                },
                {
                    "last_affected": "42.1"
                },
                {
                    "introduced": "42.2"
                },
                {
                    "last_affected": "42.2"
                }
            ],
            "vendor_product": "opensuse:leap",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "13.2"
                },
                {
                    "last_affected": "13.2"
                }
            ],
            "vendor_product": "opensuse:opensuse",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "18c"
                },
                {
                    "last_affected": "18c"
                }
            ],
            "vendor_product": "oracle:database_server",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:a:oracle:jdk:1.6.0:update161:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:jdk:1.7.0:update151:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:jdk:1.8.0:update144:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "1.6.0-update161"
                },
                {
                    "last_affected": "1.6.0-update161"
                },
                {
                    "introduced": "1.7.0-update151"
                },
                {
                    "last_affected": "1.7.0-update151"
                },
                {
                    "introduced": "1.8.0-update144"
                },
                {
                    "last_affected": "1.8.0-update144"
                }
            ],
            "vendor_product": "oracle:jdk",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:a:oracle:jre:1.6.0:update161:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:jre:1.7.0:update151:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:jre:1.8.0:update144:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "1.6.0-update161"
                },
                {
                    "last_affected": "1.6.0-update161"
                },
                {
                    "introduced": "1.7.0-update151"
                },
                {
                    "last_affected": "1.7.0-update151"
                },
                {
                    "introduced": "1.8.0-update144"
                },
                {
                    "last_affected": "1.8.0-update144"
                }
            ],
            "vendor_product": "oracle:jre",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "6.0"
                },
                {
                    "last_affected": "6.0"
                },
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_desktop",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "7.4"
                },
                {
                    "last_affected": "7.4"
                },
                {
                    "introduced": "7.5"
                },
                {
                    "last_affected": "7.5"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_eus",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "6.0"
                },
                {
                    "last_affected": "6.0"
                },
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_server",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "6.0"
                },
                {
                    "last_affected": "6.0"
                },
                {
                    "introduced": "7.0"
                },
                {
                    "last_affected": "7.0"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_workstation",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "5.8"
                },
                {
                    "last_affected": "5.8"
                }
            ],
            "vendor_product": "redhat:satellite",
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/madler/zlib

Affected ranges

Type
GIT
Repo
https://github.com/madler/zlib
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.2.0"
        },
        {
            "fixed": "1.2.9"
        }
    ],
    "cpe": "cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.2.0
v1.2.0.1
v1.2.0.2
v1.2.0.3
v1.2.0.4
v1.2.0.5
v1.2.0.6
v1.2.0.7
v1.2.0.8
v1.2.1
v1.2.1.1
v1.2.1.2
v1.2.2
v1.2.2.1
v1.2.2.2
v1.2.2.3
v1.2.2.4
v1.2.3
v1.2.3.1
v1.2.3.2
v1.2.3.3
v1.2.3.4
v1.2.3.5
v1.2.3.6
v1.2.3.7
v1.2.3.8
v1.2.3.9
v1.2.4
v1.2.4-pre1
v1.2.4-pre2
v1.2.4.1
v1.2.4.2
v1.2.4.3
v1.2.4.4
v1.2.4.5
v1.2.5
v1.2.5.1
v1.2.5.2
v1.2.5.3
v1.2.6
v1.2.6.1
v1.2.7
v1.2.7.1
v1.2.7.2
v1.2.7.3
v1.2.8

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "16120810892851687554789220157819832702",
                "131827276427891043182256510196340875300",
                "189513208101419307945534658579998871654",
                "212147175082612510136412243030409560140",
                "299085759267730258754641938507926344080",
                "138959356155413799645705262600700520329",
                "29752084737358720135606731688432604107",
                "166620327939650871483308933286046278470"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "contrib/infback9/inftree9.c"
        },
        "signature_version": "v1",
        "id": "CVE-2016-9843-414fe37a",
        "source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "7520686413246627020450369966414567813",
                "185218452507105074344466240122345085312",
                "122598993764574949696391344028951255785",
                "68790856490769415000555817960458189898",
                "312396610066626601976161403606852569542",
                "58290635503586024135687246048442384320",
                "56257635472176494025514288891627516122",
                "48419906790453504580546155601585011871",
                "129288830573974287994851663631918110070",
                "309613971747137665366059309652626476656",
                "59808224210313279059403352897595966020"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "crc32.c"
        },
        "signature_version": "v1",
        "id": "CVE-2016-9843-650ecf33",
        "source": "https://github.com/madler/zlib/commit/d1d577490c15a0c6862473d7576352a9f18ef811",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "33289512042373412906093149139436580830",
                "91426820839317131268716791780186008144",
                "194818944693421866592958753112657371532",
                "159668138545083466055711927804961193023",
                "255066741664144691720111386013603848817",
                "234232056215069776200927132383547217084",
                "295366361648995060731826038642910043574",
                "194364176202057146808626712171096427014"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "inftrees.c"
        },
        "signature_version": "v1",
        "id": "CVE-2016-9843-7d837108",
        "source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
        "deprecated": false
    },
    {
        "target": {
            "file": "zconf.h"
        },
        "digest": {
            "line_hashes": [
                "173123370633123651154244949134281019542",
                "102273106005205754638040113472517884264",
                "235429814244466703824677965529538273675",
                "208303993750882978934021550073336842459",
                "97615609550968706431926448181519994863",
                "339118080829838946074693924107468946553",
                "80218173194119430334455345176075092856",
                "221115080022463896686917755184628890434",
                "220779142876063203106760351651649795828",
                "79972837918061490055760410628729165483",
                "29640572416293066614062894907893542972",
                "320836455951002542724053434768351830366",
                "278439570502606989562359642144711240921",
                "74969605840670941905966442808748242415",
                "136349982313411503433050181948921111059",
                "84828482625013498067679033752823325859",
                "218156909012989000717970859258362570251",
                "156120690550699675574548547437792604157",
                "174169894385923384555886757688589868129",
                "113887265610536653913694580851125688715",
                "322944331613534704823013669100696288875",
                "25052244974639821325585794070234606822",
                "38325901798038084643343130133098808807",
                "158002972493212489475769473812998149461",
                "292758423975469462340735089873782351214",
                "197319885884091558389402997168622303229",
                "273529858872929722013164257392580258347",
                "2188558013403878625577241987667171928",
                "227718873515223558132286010362181398299",
                "337146253929636158546926301773569599342",
                "276954032770302743552966193594550874576",
                "326215511158024088703961555581128655326",
                "243619819439693214143230160079414937501",
                "232483367442315974246589415647223061426",
                "260395415480728946097742438941645713965",
                "292290712618831869667048484348647386677",
                "191647618147979755276168823006196468103",
                "219013074033810971796049774630081821884",
                "205564429641538400226903564968255480612",
                "294498949750680192840586029840089044143",
                "183398131489758762038008857864289906980",
                "69378252258223222776676769656103498778",
                "150063933148831471523654235222726000523",
                "160919057829188140111342717977171904200",
                "113985210579133651988131412870508958926",
                "236797731968003545657916862894293146441"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "id": "CVE-2016-9843-877aa23a",
        "source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
        "deprecated": false
    },
    {
        "target": {
            "file": "deflate.c"
        },
        "digest": {
            "line_hashes": [
                "241551680136109100503375360648810826978",
                "68187369923040033918172656615963607133",
                "297761764425146664349507739115654243055"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "id": "CVE-2016-9843-ebd0da57",
        "source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-11T18:15:07Z"
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9843.json"

Git / github.com/mariadb/server

Affected ranges

Type
GIT
Repo
https://github.com/mariadb/server
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.5.0"
        },
        {
            "fixed": "5.5.62"
        },
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.0.37"
        },
        {
            "introduced": "10.1.0"
        },
        {
            "fixed": "10.1.37"
        },
        {
            "introduced": "10.2.0"
        },
        {
            "fixed": "10.2.19"
        },
        {
            "introduced": "10.3.0"
        },
        {
            "fixed": "10.3.11"
        }
    ],
    "cpe": "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

mariadb-10.*
mariadb-10.1.0
mariadb-10.1.10
mariadb-10.1.11
mariadb-10.1.12
mariadb-10.1.13
mariadb-10.1.14
mariadb-10.1.15
mariadb-10.1.16
mariadb-10.1.17
mariadb-10.1.18
mariadb-10.1.19
mariadb-10.1.2
mariadb-10.1.20
mariadb-10.1.21
mariadb-10.1.22
mariadb-10.1.23
mariadb-10.1.24
mariadb-10.1.25
mariadb-10.1.26
mariadb-10.1.27
mariadb-10.1.28
mariadb-10.1.29
mariadb-10.1.3
mariadb-10.1.30
mariadb-10.1.31
mariadb-10.1.32
mariadb-10.1.33
mariadb-10.1.34
mariadb-10.1.35
mariadb-10.1.4
mariadb-10.1.5
mariadb-10.1.6
mariadb-10.1.7
mariadb-10.1.8
mariadb-10.1.9
mariadb-10.2.0
mariadb-10.2.1
mariadb-10.2.10
mariadb-10.2.11
mariadb-10.2.12
mariadb-10.2.13
mariadb-10.2.14
mariadb-10.2.15
mariadb-10.2.16
mariadb-10.2.18
mariadb-10.2.2
mariadb-10.2.5
mariadb-10.3.0
mariadb-10.3.1
mariadb-10.3.10
mariadb-10.3.2
mariadb-10.3.4
mariadb-10.3.5
mariadb-10.3.6
mariadb-10.3.7

Database specific

vanir_signatures
[
    {
        "target": {
            "file": "mysys/mf_iocache2.c"
        },
        "digest": {
            "line_hashes": [
                "160075039351122944864225182554874669088",
                "79298247766313756764199076124200846221",
                "45115464249083926102003093201691213873",
                "234850493844753889546639429561578022423",
                "28144202877714812540506170033579428584",
                "64207172708277179404454160631042475789",
                "237722189373658064007831416036979490253",
                "40893712863390563503154152743217547031",
                "117668516850458519561463813363427354257",
                "157614703768094946194775545036620441701",
                "15967427616295603339113842507058398295",
                "104723310754908331401965919169681994802",
                "128841576046909535802914848653453387150",
                "284907253619130800196406482515430948114",
                "58255352786302269574555313408484604557",
                "157514477970302582442983000214658193991",
                "49411501730675364796830781016823824091",
                "156754744226265852277547691043485091575",
                "151934133497638100292742275943448330976",
                "10181848583206569474669288713374153883",
                "247129231873868569546561042046461048482"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "id": "CVE-2016-9843-31d9682c",
        "source": "https://github.com/mariadb/server/commit/bac287c315b1792e7ae33f91add6a60292f9bae8",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-11T18:15:07Z"
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9843.json"

Git / github.com/mysql/mysql-server

Affected ranges

Type
GIT
Repo
https://github.com/mysql/mysql-server
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.5.0"
        },
        {
            "last_affected": "5.5.61"
        },
        {
            "introduced": "5.6.0"
        },
        {
            "last_affected": "5.6.41"
        },
        {
            "introduced": "5.7.0"
        },
        {
            "last_affected": "5.7.23"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "last_affected": "8.0.12"
        }
    ],
    "cpe": "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

mysql-3.*
mysql-3.23.22-beta
mysql-3.23.28-gamma
mysql-3.23.30-gamma
mysql-3.23.31
mysql-3.23.32
mysql-3.23.33
mysql-3.23.36
mysql-4.*
mysql-4.0.2
mysql-4.0.4
mysql-5.*
mysql-5.1.4
mysql-5.5.15
mysql-5.5.19
mysql-5.5.23
mysql-5.5.25
mysql-5.5.27
mysql-5.5.44
mysql-5.5.47
mysql-5.5.49
mysql-5.5.59
mysql-5.5.60
mysql-5.5.61
mysql-5.6.40
mysql-5.6.41
mysql-5.7.23
mysql-8.*
mysql-8.0.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9843.json"