CVE-2016-9538: Integer Overflow
tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35100.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9538?
CVE-2016-9538 is considered a high severity vulnerability due to the potential for arbitrary code execution resulting from an integer overflow.
How do I fix CVE-2016-9538?
To fix CVE-2016-9538, update the libtiff package to versions 4.1.0+git191117-2~deb10u4, 4.1.0+git191117-2~deb10u8, 4.2.0-1+deb11u4, 4.5.0-6, or 4.5.1+git230720-1.
What systems are affected by CVE-2016-9538?
CVE-2016-9538 affects versions of libtiff prior to 4.0.6, particularly on Debian-based systems with specific package versions.
What does CVE-2016-9538 impact?
CVE-2016-9538 impacts the ability of applications that use the libtiff library, potentially allowing an attacker to execute arbitrary code.
Is there a known exploit for CVE-2016-9538?
As of now, there are no public reports of active exploits specifically targeting CVE-2016-9538.