CVE-2016-9535: Buffer Overflow
MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability
Other sources
tifpredict.h and tifpredict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
— MITRE
tifpredict.h and tifpredict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow." MITRE created this CVE on their behalf. The documented Windows updates incorporate updates in LibTIFF which address this vulnerability. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9535?
CVE-2016-9535 is classified as a high severity vulnerability due to potential buffer overflows.
How do I fix CVE-2016-9535?
To fix CVE-2016-9535, upgrade to a patched version of libtiff that addresses this vulnerability.
What software versions are affected by CVE-2016-9535?
CVE-2016-9535 affects libtiff version 4.0.6 specifically.
What type of vulnerability is CVE-2016-9535?
CVE-2016-9535 is a buffer overflow vulnerability that can lead to crashes or exploit potential.
Can CVE-2016-9535 be exploited remotely?
Yes, CVE-2016-9535 can potentially be exploited remotely if the affected software is exposed to untrusted inputs.