CVE-2016-9540

Source
https://cve.org/CVERecord?id=CVE-2016-9540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-9540
Downstream
Related
Published
2016-11-22T19:59:08Z
Modified
2026-07-08T12:06:38Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."

References

Affected packages

Git / github.com/vadz/libtiff

Affected ranges

Type
GIT
Repo
https://github.com/vadz/libtiff
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "4.0.6"
        },
        {
            "last_affected":  "4.0.6"
        }
    ],
    "source":  [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.0.6
Other
Release-v4-0-6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9540.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "207524068906828631989641842792468108303",
            "length":  1112
        },
        "id":  "CVE-2016-9540-14ce97fd",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vadz/libtiff/commit/5ad9d8016fbb60109302d558f7edb2cb2a3bb8e3",
        "target":  {
            "file":  "tools/tiffcp.c",
            "function":  "DECLAREreadFunc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "195565821341471143227011566239408712014",
            "length":  1114
        },
        "id":  "CVE-2016-9540-6dbdf5a6",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vadz/libtiff/commit/5ad9d8016fbb60109302d558f7edb2cb2a3bb8e3",
        "target":  {
            "file":  "tools/tiffcp.c",
            "function":  "DECLAREwriteFunc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "34526652489744293167320693439694332065",
                "65740507902341232373190466765183987449",
                "154738245544947738771589024196496874484",
                "184235936083252003010603516386408026816",
                "34526652489744293167320693439694332065",
                "322474512737234513158984885363131714047",
                "48270571887375478153307819412452982050",
                "18898764740452236580005303907312585781"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2016-9540-92bc6797",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vadz/libtiff/commit/5ad9d8016fbb60109302d558f7edb2cb2a3bb8e3",
        "target":  {
            "file":  "tools/tiffcp.c"
        }
    }
]
vanir_signatures_modified
"2026-07-08T12:06:38Z"

Git / gitlab.com/libtiff/libtiff

Affected ranges

Type
GIT
Repo
https://gitlab.com/libtiff/libtiff
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "4.0.6"
        },
        {
            "last_affected":  "4.0.6"
        }
    ],
    "source":  "CPE_STRING"
}

Affected versions

4.*
4.0.6
v4.*
v4.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9540.json"