Out-of-bounds read in LibTIFF - CVE-2016-9273
Published: January 18, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32102
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9273
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.
Affected software
LibTIFF
tiff (Alpine package)
libtiff
Slackware Linux
Dynamic System Analysis (DSA) Preboot
tiff (Alpine package)
libtiff
Slackware Linux
Dynamic System Analysis (DSA) Preboot
How to mitigate CVE-2016-9273
Install update from vendor's website.
tiff (Alpine package) - update to 4.0.7-r0
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - update to 4.0.7
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - update to 4.0.7