CVE-2016-9448: Null Pointer Dereference
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFFSETGETC16ASCII or TIFFSETGETC32ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9448?
CVE-2016-9448 has a severity rating that indicates it can lead to denial of service due to a null pointer dereference.
How do I fix CVE-2016-9448?
To fix CVE-2016-9448, you should upgrade to a fixed version of the LibTiff library, specifically versions higher than 4.0.6.
Which software is affected by CVE-2016-9448?
CVE-2016-9448 affects LibTiff version 4.0.6 and certain versions of the 'tiff' package in Debian and openSUSE.
Can CVE-2016-9448 be exploited remotely?
Yes, CVE-2016-9448 can be exploited by remote attackers to cause a denial of service.
What are the potential impacts of CVE-2016-9448?
The potential impact of CVE-2016-9448 is a crash of the application utilizing LibTiff, leading to a denial of service.