The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.
                
            References
                    | Link | Resource | 
|---|---|
| http://bugzilla.maptools.org/show_bug.cgi?id=2579 | Issue Tracking Third Party Advisory | 
| http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00017.html | Mailing List Third Party Advisory | 
| http://www.debian.org/security/2017/dsa-3762 | Third Party Advisory | 
| http://www.openwall.com/lists/oss-security/2016/11/19/1 | Mailing List Third Party Advisory | 
| http://www.securityfocus.com/bid/94406 | Third Party Advisory VDB Entry | 
| https://security.gentoo.org/glsa/201701-16 | Third Party Advisory | 
| http://bugzilla.maptools.org/show_bug.cgi?id=2579 | Issue Tracking Third Party Advisory | 
| http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00017.html | Mailing List Third Party Advisory | 
| http://www.debian.org/security/2017/dsa-3762 | Third Party Advisory | 
| http://www.openwall.com/lists/oss-security/2016/11/19/1 | Mailing List Third Party Advisory | 
| http://www.securityfocus.com/bid/94406 | Third Party Advisory VDB Entry | 
| https://security.gentoo.org/glsa/201701-16 | Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 03:01
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://bugzilla.maptools.org/show_bug.cgi?id=2579 - Issue Tracking, Third Party Advisory | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00017.html - Mailing List, Third Party Advisory | |
| References | () http://www.debian.org/security/2017/dsa-3762 - Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2016/11/19/1 - Mailing List, Third Party Advisory | |
| References | () http://www.securityfocus.com/bid/94406 - Third Party Advisory, VDB Entry | |
| References | () https://security.gentoo.org/glsa/201701-16 - Third Party Advisory | 
Information
                Published : 2017-01-27 17:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-9453
Mitre link : CVE-2016-9453
CVE.ORG link : CVE-2016-9453
JSON object : View
Products Affected
                libtiff
- libtiff
debian
- debian_linux
opensuse
- opensuse
CWE
                
                    
                        
                        CWE-787
                        
            Out-of-bounds Write
