Security update for zlib
This update for zlib fixes the following issues: CVE-2016-9843: Big-endian out-of-bounds pointer (bsc#1013882) CVE-2016-9842: Undefined Left Shift of Negative Number (bsc#1003580) CVE-2016-9840 CVE-2016-9841: Out-of-bounds pointer arithmetic in inftrees.c (bsc#1003579) Incompatible declarations for external linkage function deflate (bsc#1003577)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for zlib fixes the following issues: CVE-2016-9843: Big-endian out-of-bounds pointer (bsc#1013882) CVE-2016-9842: Undefined Left Shift of Negative Number (bsc#1003580) CVE-2016-9840 CVE-2016-9841: Out-of-bounds pointer arithmetic in inftrees.c (bsc#1003579) Incompatible declarations for external linkage function deflate (bsc#1003577)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1003577
- https://bugzilla.suse.com/1003579
- https://bugzilla.suse.com/1003580
- https://bugzilla.suse.com/1013882
- https://www.suse.com/security/cve/CVE-2016-9840
- https://www.suse.com/security/cve/CVE-2016-9841
- https://www.suse.com/security/cve/CVE-2016-9842
- https://www.suse.com/security/cve/CVE-2016-9843
- https://www.suse.com/support/update/announcement/2017/suse-su-20170004-1/