Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9535

Опубликовано: 22 нояб. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

РелизСтатусПримечание
artful

not-affected

4.0.7-1
devel

not-affected

4.0.7-1
esm-infra-legacy/trusty

released

4.0.3-7ubuntu0.6
esm-infra-legacy/xenial

released

4.0.6-1ubuntu0.1
esm-infra/xenial

released

4.0.6-1ubuntu0.1
precise

ignored

end of life
precise/esm

ignored

trusty

released

4.0.3-7ubuntu0.6
trusty/esm

released

4.0.3-7ubuntu0.6
upstream

released

4.0.7-1

Показывать по

EPSS

Процентиль: 91%
0.04767
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
почти 10 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

CVSS3: 9.8
nvd
больше 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

CVSS3: 4
msrc
10 месяцев назад

MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability

CVSS3: 9.8
debian
больше 9 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that ...

CVSS3: 9.8
github
около 4 лет назад

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

EPSS

Процентиль: 91%
0.04767
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3