Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9535

Опубликовано: 04 нояб. 2016
Источник: redhat
CVSS3: 7
CVSS2: 5.1
EPSS Низкий

Описание

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libtiffWill not fix
Red Hat Enterprise Linux 7compat-libtiff3Will not fix
Red Hat Enterprise Linux 6libtiffFixedRHSA-2017:022501.02.2017
Red Hat Enterprise Linux 7libtiffFixedRHSA-2017:022501.02.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1397755libtiff: Predictor heap-buffer-overflow

EPSS

Процентиль: 72%
0.00739
Низкий

7 High

CVSS3

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

CVSS3: 9.8
nvd
почти 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

CVSS3: 4
msrc
20 дней назад

MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability

CVSS3: 9.8
debian
почти 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that ...

CVSS3: 9.8
github
больше 3 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

EPSS

Процентиль: 72%
0.00739
Низкий

7 High

CVSS3

5.1 Medium

CVSS2