tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2017-0225.html | |
http://www.debian.org/security/2017/dsa-3844 | |
http://www.securityfocus.com/bid/94484 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94744 | |
https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1 | Issue Tracking Patch Third Party Advisory |
https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33 | Issue Tracking Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2016-11-22 19:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-9535
Mitre link : CVE-2016-9535
CVE.ORG link : CVE-2016-9535
JSON object : View
Products Affected
libtiff
- libtiff
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer