CVE-2016-0225
published 2016-02-29CVE-2016-0225: IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive…
PriorityP421medium4.9CVSS 3.0
AVNACLPRHUINSUCHINAN
EPSS
1.10%
61.7th percentile
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9536 libtiff: t2p_process_jpeg_strip heap-buffer-overflow
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9536 [CRITICAL] CVE-2016-9536 libtiff: t2p_process_jpeg_strip heap-buffer-overflow
CVE-2016-9536 libtiff: t2p_process_jpeg_strip heap-buffer-overflow
It was found that tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip().
Upstream patch:
https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-5173a9b3b48146e4fd86d7b9b346115e
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397781]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397782]
Affects: epel-7 [bug 1397783]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:0225 https://rhn.redhat.com/errata/RHSA-2017-0225.html
Bugzilla
CVE-2016-9537 libtiff: Out-of-bounds write vulnerabilities in tools/tiffcrop.c
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9537 [CRITICAL] CVE-2016-9537 libtiff: Out-of-bounds write vulnerabilities in tools/tiffcrop.c
CVE-2016-9537 libtiff: Out-of-bounds write vulnerabilities in tools/tiffcrop.c
It was found that tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers.
Upstream patch:
https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-c8b4b355f9b5c06d585b23138e1c185f
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397781]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397782]
Affects: epel-7 [bug 1397783]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:0225 https://rhn.redhat.com/errata/RHSA-2017-0225.html
Bugzilla
CVE-2016-9534 libtiff: TIFFFlushData1 heap-buffer-overflow
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9534 [CRITICAL] CVE-2016-9534 libtiff: TIFFFlushData1 heap-buffer-overflow
CVE-2016-9534 libtiff: TIFFFlushData1 heap-buffer-overflow
It was found that tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members.
Upstream patch:
https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-5be5ce02d0dea67050d5b2a10102d1ba
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397781]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397782]
Affects: epel-7 [bug 1397783]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:0225 https://rhn.redhat.com/errata/RHSA-2017-0225.html
Bugzilla
CVE-2016-9540 libtiff: cpStripToTile heap-buffer-overflow
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9540 [CRITICAL] CVE-2016-9540 libtiff: cpStripToTile heap-buffer-overflow
CVE-2016-9540 libtiff: cpStripToTile heap-buffer-overflow
It was found that tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width
Upstream patch:
https://github.com/vadz/libtiff/commit/5ad9d8016fbb60109302d558f7edb2cb2a3bb8e3
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397781]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397782]
Affects: epel-7 [bug 1397783]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:0225 https://rhn.redhat.com/errata/RHSA-2017-0225.html
Bugzilla
CVE-2016-9533 libtiff: PixarLog horizontalDifference heap-buffer-overflow
bugzilla·2016-11-23·CVSS 9.8
CVE-2016-9533 [CRITICAL] CVE-2016-9533 libtiff: PixarLog horizontalDifference heap-buffer-overflow
CVE-2016-9533 libtiff: PixarLog horizontalDifference heap-buffer-overflow
It was found that tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers.
Upstream patch:
https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-bdc795f6afeb9558c1012b3cfae729ef
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397781]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1397782]
Affects: epel-7 [bug 1397783]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:0225 https://rhn.redhat.com/errata/RHSA-2017-0225.html
2016-02-29
Published