Related Vulnerabilities: CVE-2016-9538  

It was found that tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.

Severity Low

Remote Yes

Type Denial of service

Description

It was found that tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow.

AVG-86 lib32-libtiff 4.0.6-2 4.0.7-1 Critical Fixed

AVG-85 libtiff 4.0.6-2 4.0.7-1 Critical Fixed

25 Nov 2016 ASA-201611-27 AVG-86 lib32-libtiff Critical multiple issues

25 Nov 2016 ASA-201611-26 AVG-85 libtiff Critical multiple issues

https://github.com/vadz/libtiff/commit/43c0b81a818640429317c80fea1e66771e85024b