Bugzilla – Bug 1011842
VUL-0: CVE-2016-9537: tiff: Out-of-bounds write vulnerabilities in tools/tiffcrop.c
Last modified: 2018-11-30 12:36:13 UTC
rh#1397760 It was found that tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Upstream patch: https://github.com/vadz/libtiff/commit/83a4b92815ea04969d494416eaae3d4c6b338e4a#diff-c8b4b355f9b5c06d585b23138e1c185f References: https://bugzilla.redhat.com/show_bug.cgi?id=1397760 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9537 http://www.cvedetails.com/cve/CVE-2016-9537/
tools/tiffcrop.c is only available in SLE-12. All other codestreams seams to be not affected.
bugbot adjusting priority
The fix is already in 12/tiff as far as I can see. Suggest to close as fixed.
already fixed