CVE-2016-9535

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
22/11/2016
Last modified:
12/04/2025

Description

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*