tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2017-0225.html | |
http://www.debian.org/security/2017/dsa-3844 | |
http://www.securityfocus.com/bid/94484 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94744 | |
https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1 | Issue Tracking Patch Third Party Advisory |
https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33 | Issue Tracking Patch Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2017-0225.html | |
http://www.debian.org/security/2017/dsa-3844 | |
http://www.securityfocus.com/bid/94484 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94744 | |
https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1 | Issue Tracking Patch Third Party Advisory |
https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33 | Issue Tracking Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 03:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2017-0225.html - | |
References | () http://www.debian.org/security/2017/dsa-3844 - | |
References | () http://www.securityfocus.com/bid/94484 - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/94744 - | |
References | () https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33 - Issue Tracking, Patch, Third Party Advisory |
Information
Published : 2016-11-22 19:59
Updated : 2024-11-21 03:01
NVD link : CVE-2016-9535
Mitre link : CVE-2016-9535
CVE.ORG link : CVE-2016-9535
JSON object : View
Products Affected
libtiff
- libtiff
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer