tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
Advisories
Source ID Title
Debian DLA Debian DLA DLA-880-1 tiff3 security update
Debian DSA Debian DSA DSA-3762-1 tiff security update
Debian DSA Debian DSA DSA-3844-1 tiff security update
EUVD EUVD EUVD-2016-10341 tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."
Ubuntu USN Ubuntu USN USN-3212-1 LibTIFF vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T02:50:38.565Z

Reserved: 2016-11-21T00:00:00

Link: CVE-2016-9535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-11-22T19:59:03.387

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-9535

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-11-04T00:00:00Z

Links: CVE-2016-9535 - Bugzilla

cve-icon OpenCVE Enrichment

No data.