Related Vulnerabilities: CVE-2016-9540  

It was found that tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds heap write on tiled images with odd tile width versus image width. This has also been reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."

Severity High

Remote Yes

Type Arbitrary code execution

Description

It was found that tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds heap write on tiled images with odd tile width versus image width. This has also been reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."

AVG-86 lib32-libtiff 4.0.6-2 4.0.7-1 Critical Fixed

AVG-85 libtiff 4.0.6-2 4.0.7-1 Critical Fixed

25 Nov 2016 ASA-201611-27 AVG-86 lib32-libtiff Critical multiple issues

25 Nov 2016 ASA-201611-26 AVG-85 libtiff Critical multiple issues

https://github.com/vadz/libtiff/commit/5ad9d8016fbb60109302d558f7edb2cb2a3bb8e3