tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
References
Link | Resource |
---|---|
https://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1 | Issue Tracking Patch Third Party Advisory |
https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33 | Issue Tracking Patch Third Party Advisory |
http://www.securityfocus.com/bid/94484 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94744 | |
http://www.debian.org/security/2017/dsa-3844 | |
http://rhn.redhat.com/errata/RHSA-2017-0225.html |
Configurations
Information
Published : 2016-11-22 11:59
Updated : 2018-01-04 18:31
NVD link : CVE-2016-9535
Mitre link : CVE-2016-9535
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
libtiff
- libtiff