HTTP: LibTIFF tiffcrop Integer Overflow

An out-of-bounds write vulnerability exists in LibTIFF tiffcrop component. Successful exploitation of this vulnerability could lead to denial of service conditions or, in the worst case, arbitrary code execution in the context of the affected application.

Extended Description

tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.

Affected Products

Libtiff libtiff

References

CVE: CVE-2016-9537

Short Name
HTTP:STC:DL:CVE-2016-9537-IOV
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-9537 Integer LibTIFF Overflow tiffcrop
Release Date
02/21/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Libtiff

CVSS Score

7.5

Found a potential security threat?