CVE Vulnerabilities

CVE-2016-9448

NULL Pointer Dereference

Published: Jan 27, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW

The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Libtiff Libtiff 4.0.6 (including) 4.0.6 (including)
Opensuse Opensuse 13.2 (including) 13.2 (including)
Tiff Ubuntu esm-infra-legacy/trusty *
Tiff Ubuntu esm-infra/xenial *
Tiff Ubuntu precise *
Tiff Ubuntu precise/esm *
Tiff Ubuntu trusty *
Tiff Ubuntu trusty/esm *
Tiff Ubuntu upstream *
Tiff Ubuntu vivid/stable-phone-overlay *
Tiff Ubuntu wily *
Tiff Ubuntu xenial *
Tiff Ubuntu yakkety *

Potential Mitigations

References