CVE-2016-9540 describes an out-of-bounds write vulnerability in tools/tiffcp.c of libtiff version 4.0.6, specifically affecting tiled images with an odd tile width compared to the image width. This critical vulnerability (CVSS 9.8) can be exploited remotely over the network with low complexity and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the CISA KEV catalog, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.6CPE matchmatch criteria | cpe:2.3:a:libtiff:libtiff:4.0.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.