CVE-2016-9453: High severity LibTIFF libtiff vulnerability
The t2preadwritepdfimagetile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAGJPEGTABLES of length one.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9453?
CVE-2016-9453 is classified as a high severity vulnerability due to its potential to cause denial of service and possible arbitrary code execution.
How do I fix CVE-2016-9453?
To fix CVE-2016-9453, update to the patched versions of the tiff package or libtiff as specified by your system's package manager.
Which versions of libtiff are affected by CVE-2016-9453?
CVE-2016-9453 affects versions of libtiff prior to 4.0.7.
What types of attacks can be performed using CVE-2016-9453?
CVE-2016-9453 can be exploited for remote denial of service attacks or potentially executing arbitrary code via malformed JPEG files.
On which operating systems does CVE-2016-9453 impact the tiff package?
CVE-2016-9453 impacts the tiff package on operating systems such as Debian and openSUSE.