CVE-2016-9535
Last modified
CVE-2016-9535 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow.". EPSS estimates a 4.77% chance of exploitation in the next 30 days.
Description
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libtiff | Libtiff | 4.0.6 |
References
- http://www.securityfocus.com/bid/94484Third Party Advisory, VDB Entry
- https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1Issue Tracking, Patch, Third Party Advisory
- https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33Issue Tracking, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94484Third Party Advisory, VDB Entry
- https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1Issue Tracking, Patch, Third Party Advisory
- https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9535?
How severe is CVE-2016-9535?
How do I fix CVE-2016-9535?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-9529Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9530Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9531Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-9532Integer overflow in the writeBufferToSeparateStrips function…
- CVE-2016-9533tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vuln…
- CVE-2016-9534tif_write.c in libtiff 4.0.6 has an issue in the error code …
- CVE-2016-9536tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vu…
- CVE-2016-9537tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vu…
- CVE-2016-9538tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer …
- CVE-2016-9539tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read …
- CVE-2016-9540tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write o…
- CVE-2016-9553The Sophos Web Appliance (version 4.2.1.3) is vulnerable to …
Are you affected by CVE-2016-9535?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
