CVE-2016-9538 — Integer Overflow or Wraparound in Libtiff
Severity
9.8CRITICALNVD
EPSS
0.4%
top 38.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 22
Latest updateMay 17
Description
tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35100.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages3 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
4Apple▶
CVE-2016-9538: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite↗2017-03-27
Red Hat▶
libtiff: Integer overflow leads to reading undefined buffer in readContigStripsIntoBuffer()↗2016-10-08
Debian▶
CVE-2016-9538: tiff - tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsI...↗2016
💬Community
4Bugzilla▶
CVE-2016-9448 CVE-2016-9453 CVE-2016-9532 CVE-2016-9533 CVE-2016-9534 CVE-2016-9535 CVE-2016-9536 CVE-2016-9537 CVE-2016-9538 CVE-2016-9539 CVE-2016-9540 mingw-libtiff: various flaws [fedora-all]↗2016-11-23
Bugzilla▶
CVE-2016-9448 CVE-2016-9453 CVE-2016-9532 CVE-2016-9533 CVE-2016-9534 CVE-2016-9535 CVE-2016-9536 CVE-2016-9537 CVE-2016-9538 CVE-2016-9539 CVE-2016-9540 mingw-libtiff: various flaws [epel-7]↗2016-11-23
Bugzilla▶
CVE-2016-9448 CVE-2016-9453 CVE-2016-9532 CVE-2016-9533 CVE-2016-9534 CVE-2016-9535 CVE-2016-9536 CVE-2016-9537 CVE-2016-9538 CVE-2016-9539 CVE-2016-9540 libtiff: various flaws [fedora-all]↗2016-11-23
Bugzilla▶
CVE-2016-9538 libtiff: Integer overflow leads to reading undefined buffer in readContigStripsIntoBuffer()↗2016-11-23