CVE-2016-9840

Priority
Description
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have
unspecified impact by leveraging improper pointer arithmetic.
Notes
ebarrettosince v3.1.1-1, rsync uses the included zlib instead of system zlib
Package
Source: rsync (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):not-affected (code not present)
Ubuntu 14.04 ESM (Trusty Tahr):not-affected (code not present)
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):needed
Ubuntu 19.04 (Disco Dingo):released (3.1.3-6)
Ubuntu 19.10 (Eoan Ermine):released (3.1.3-6)
Ubuntu 20.04 (Focal Fossa):released (3.1.3-6)
Package
Source: zlib (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 ESM (Trusty Tahr):needed
Ubuntu 16.04 LTS (Xenial Xerus):released (1:1.2.8.dfsg-2ubuntu4.3)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (1:1.2.11.dfsg-0ubuntu2)
Ubuntu 19.04 (Disco Dingo):not-affected (1:1.2.11.dfsg-0ubuntu2)
Ubuntu 19.10 (Eoan Ermine):not-affected (1:1.2.11.dfsg-0ubuntu2)
Ubuntu 20.04 (Focal Fossa):not-affected (1:1.2.11.dfsg-0ubuntu2)
Patches:
Upstream:https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0
More Information

Updated: 2020-01-22 22:14:21 UTC (commit 6c4e51ef9718e6eab9cfb913cd1a2002b2106dc3)