First published: Tue Nov 22 2016(Updated: )
tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35100.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/tiff | 4.1.0+git191117-2~deb10u4 4.1.0+git191117-2~deb10u8 4.2.0-1+deb11u4 4.5.0-6 4.5.1+git230720-1 | |
libtiff | =4.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9538 is considered a high severity vulnerability due to the potential for arbitrary code execution resulting from an integer overflow.
To fix CVE-2016-9538, update the libtiff package to versions 4.1.0+git191117-2~deb10u4, 4.1.0+git191117-2~deb10u8, 4.2.0-1+deb11u4, 4.5.0-6, or 4.5.1+git230720-1.
CVE-2016-9538 affects versions of libtiff prior to 4.0.6, particularly on Debian-based systems with specific package versions.
CVE-2016-9538 impacts the ability of applications that use the libtiff library, potentially allowing an attacker to execute arbitrary code.
As of now, there are no public reports of active exploits specifically targeting CVE-2016-9538.