CVE-2016-9297: High severity LibTIFF libtiff vulnerability
Published Jan 18, 2017
·Updated
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFFSETGETC16ASCII or TIFFSETGETC32ASCII tag values.
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.6
Remediation
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9297?
CVE-2016-9297 has a severity level that can lead to denial of service due to out-of-bounds read.
2
How do I fix CVE-2016-9297?
To fix CVE-2016-9297, upgrade to LibTiff version 4.1.0 or later.
3
Which software versions are affected by CVE-2016-9297?
CVE-2016-9297 affects LibTiff version 4.0.6 and earlier releases of the tiff package.
4
What type of attack does CVE-2016-9297 involve?
CVE-2016-9297 involves a denial of service attack caused by crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.
5
Is CVE-2016-9297 a remote code execution vulnerability?
No, CVE-2016-9297 is classified as a denial of service vulnerability, not a remote code execution vulnerability.