CVE-2016-9535
Last modified
CVE-2016-9535 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow.". EPSS estimates a 4.77% chance of exploitation in the next 30 days.
Description
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libtiff | Libtiff | 4.0.6 |
References
- http://www.securityfocus.com/bid/94484Third Party Advisory, VDB Entry
- https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1Issue Tracking, Patch, Third Party Advisory
- https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33Issue Tracking, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94484Third Party Advisory, VDB Entry
- https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1Issue Tracking, Patch, Third Party Advisory
- https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9535?
How severe is CVE-2016-9535?
How do I fix CVE-2016-9535?
Are you affected by CVE-2016-9535?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
