CVE-2016-9535

Source
https://cve.org/CVERecord?id=CVE-2016-9535
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9535.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-9535
Downstream
Related
Published
2016-11-22T19:59:03.387Z
Modified
2026-05-17T11:54:33.398323801Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

tifpredict.h and tifpredict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

References

Affected packages