PT-2016-7772 · Libtiff+1 · Libtiff+1

Axel Souchet

·

Publicado

2016-11-22

·

Atualizado

2024-06-15

·

CVE-2016-9538

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libtiff version 4.0.6
Description The issue arises from a uint16 integer overflow in the readContigStripsIntoBuffer() function, located in tools/tiffcrop.c, causing the program to read an undefined buffer.
Recommendations For libtiff version 4.0.6, consider updating to a newer version that addresses this issue, as the current version is affected by the integer overflow in the readContigStripsIntoBuffer() function.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9538
DLA-795-1
DSA-3762-1
OPENSUSE-SU-2024:11461-1
USN-3212-1
USN-3212-2

Produtos afetados

Ubuntu
Libtiff