CVE-2016-9540: Buffer Overflow
Published Nov 22, 2016
·Updated
tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.6
Remediation
Event History
Nov 22, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9540?
CVE-2016-9540 is classified as a high severity vulnerability due to its potential for heap buffer overflow exploitation.
2
How do I fix CVE-2016-9540?
To mitigate CVE-2016-9540, update libtiff to version 4.1.0+git191117-2~deb10u4 or later.
3
Which versions of libtiff are affected by CVE-2016-9540?
CVE-2016-9540 affects libtiff version 4.0.6 and potentially earlier versions.
4
What type of vulnerability is CVE-2016-9540?
CVE-2016-9540 is an out-of-bounds write vulnerability occurring on tiled images with specific dimensions.
5
What are the consequences of exploiting CVE-2016-9540?
Exploitation of CVE-2016-9540 could allow an attacker to execute arbitrary code or crash the application.