CVE-2016-9537: Buffer Overflow
Published Nov 22, 2016
·Updated
tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.6
Remediation
Event History
Nov 22, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9537?
The severity of CVE-2016-9537 is considered high due to the potential for out-of-bounds write vulnerabilities leading to memory corruption.
2
How do I fix CVE-2016-9537?
To fix CVE-2016-9537, upgrade to tiff versions 4.1.0+git191117-2~deb10u4 or later, or apply available patches.
3
What software is affected by CVE-2016-9537?
CVE-2016-9537 affects libtiff version 4.0.6 and potentially earlier versions.
4
Can CVE-2016-9537 be exploited remotely?
Yes, CVE-2016-9537 could potentially be exploited remotely if an attacker can manipulate input to the vulnerable software.
5
What are the potential impacts of CVE-2016-9537?
The potential impacts of CVE-2016-9537 include application crashes, data corruption, and unauthorized access to system memory.