CVE-2016-9535
CVE-2016-9535
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 4.8%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
22 nov 2016Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://rhn.redhat.com/errata/RHSA-2017-0225.htmlhttps://github.com/vadz/libtiff/commit/3ca657a8793dd011bf869695d72ad31c779c3cc1https://github.com/vadz/libtiff/commit/6a984bf7905c6621281588431f384e79d11a2e33http://www.debian.org/security/2017/dsa-3844http://www.securityfocus.com/bid/94484http://www.securityfocus.com/bid/94744