First published: Tue Nov 22 2016(Updated: )
tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libtiff | =4.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9539 has been assessed as a significant vulnerability due to the potential for out-of-bounds read, which could lead to information leakage or application crashes.
To address CVE-2016-9539, upgrade libtiff to version 4.0.7 or later, which contains the necessary patches.
CVE-2016-9539 specifically affects libtiff version 4.0.6.
CVE-2016-9539 is categorized as an out-of-bounds read vulnerability.
CVE-2016-9539 was reported in the context of libtiff 4.0.6, indicating a vulnerability present in that specific version.