inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9840.json"
[
{
"id": "CVE-2016-9840-414fe37a",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"16120810892851687554789220157819832702",
"131827276427891043182256510196340875300",
"189513208101419307945534658579998871654",
"212147175082612510136412243030409560140",
"299085759267730258754641938507926344080",
"138959356155413799645705262600700520329",
"29752084737358720135606731688432604107",
"166620327939650871483308933286046278470"
]
},
"signature_version": "v1",
"source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
"target": {
"file": "contrib/infback9/inftree9.c"
},
"deprecated": false
},
{
"id": "CVE-2016-9840-877aa23a",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"173123370633123651154244949134281019542",
"102273106005205754638040113472517884264",
"235429814244466703824677965529538273675",
"208303993750882978934021550073336842459",
"97615609550968706431926448181519994863",
"339118080829838946074693924107468946553",
"80218173194119430334455345176075092856",
"221115080022463896686917755184628890434",
"220779142876063203106760351651649795828",
"79972837918061490055760410628729165483",
"29640572416293066614062894907893542972",
"320836455951002542724053434768351830366",
"278439570502606989562359642144711240921",
"74969605840670941905966442808748242415",
"136349982313411503433050181948921111059",
"84828482625013498067679033752823325859",
"218156909012989000717970859258362570251",
"156120690550699675574548547437792604157",
"174169894385923384555886757688589868129",
"113887265610536653913694580851125688715",
"322944331613534704823013669100696288875",
"25052244974639821325585794070234606822",
"38325901798038084643343130133098808807",
"158002972493212489475769473812998149461",
"292758423975469462340735089873782351214",
"197319885884091558389402997168622303229",
"273529858872929722013164257392580258347",
"2188558013403878625577241987667171928",
"227718873515223558132286010362181398299",
"337146253929636158546926301773569599342",
"276954032770302743552966193594550874576",
"326215511158024088703961555581128655326",
"243619819439693214143230160079414937501",
"232483367442315974246589415647223061426",
"260395415480728946097742438941645713965",
"292290712618831869667048484348647386677",
"191647618147979755276168823006196468103",
"219013074033810971796049774630081821884",
"205564429641538400226903564968255480612",
"294498949750680192840586029840089044143",
"183398131489758762038008857864289906980",
"69378252258223222776676769656103498778",
"150063933148831471523654235222726000523",
"160919057829188140111342717977171904200",
"113985210579133651988131412870508958926",
"236797731968003545657916862894293146441"
]
},
"signature_version": "v1",
"source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
"target": {
"file": "zconf.h"
},
"deprecated": false
},
{
"id": "CVE-2016-9840-c5f344c4",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"79922679965347110745734698915726632467",
"126813590579008290988718395478645426206",
"79466596218979115230947295705213292393",
"94908522895392918179330397374303322654",
"294878633993268850114778284316336215255",
"45629984547848664636655317045532794035",
"116847805198357221433888060203111502041",
"312136188528093063192158590599941715254",
"54270934100445027986781242788444508427",
"151244602054367791046613768817959193697",
"182299172507133003738586974100950863836",
"287898435384129613401554161468337708342",
"165985360513289330686611297477254368814",
"275321615747459570033077014648560830547",
"70348488676879259643634764804252428984",
"295378974609983581304343450587863375323",
"281587176543147940050594107912300113027",
"291357719346107022770774239922984576091",
"5363548009795485230402450341246148900",
"283614953693141663496762238152828872207",
"317432809742657110140968209661147809307",
"223316103943005991916374936548405181986",
"94843072090250528147617254384594442333",
"207902361503503787683588524899448874944",
"128236543350826831504384697314118593786",
"17736424622891055567985379507175510801",
"99172734391354959660529588307945130416",
"168640863699306485229530538896427329407",
"22889291697561298601158473495398811020",
"99489743347852376068360184828245211593"
]
},
"signature_version": "v1",
"source": "https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0",
"target": {
"file": "inftrees.c"
},
"deprecated": false
},
{
"id": "CVE-2016-9840-ebd0da57",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"241551680136109100503375360648810826978",
"68187369923040033918172656615963607133",
"297761764425146664349507739115654243055"
]
},
"signature_version": "v1",
"source": "https://github.com/madler/zlib/commit/2fa463bacfff79181df1a5270fb67cc679a53e71",
"target": {
"file": "deflate.c"
},
"deprecated": false
}
]