CVE-2016-9533: Buffer Overflow
Published Nov 22, 2016
·Updated
tifpixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDifference heap-buffer-overflow."
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.6
Remediation
Event History
Nov 22, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9533?
CVE-2016-9533 is classified as a high-severity vulnerability due to its potential for causing out-of-bounds writes in heap allocated buffers.
2
How do I fix CVE-2016-9533?
To fix CVE-2016-9533, upgrade to a fixed version of the libtiff package such as 4.1.0+git191117-2~deb10u4 or higher.
3
Which versions of libtiff are affected by CVE-2016-9533?
CVE-2016-9533 specifically affects version 4.0.6 of libtiff.
4
What types of systems are vulnerable to CVE-2016-9533?
Systems using libtiff version 4.0.6 or earlier are vulnerable to CVE-2016-9533.
5
What impact does CVE-2016-9533 have on applications?
CVE-2016-9533 may lead to application crashes or arbitrary code execution due to buffer overflow vulnerabilities.