PT-2016-7492 · None+2 · Libtiff+2

Publicado

2016-10-28

·

Atualizado

2022-04-19

·

CVE-2016-8331

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.6
Description A remote code execution issue exists in the handling of TIFF images. This is due to a type confusion vulnerability that can be triggered by a crafted TIFF document, potentially allowing remote code execution. The vulnerability can be exploited via a TIFF file delivered to the application using LibTIFF's tag extension functionality.
Recommendations For LibTIFF version 4.0.6, consider avoiding the use of TIFF files or restricting access to the tag extension functionality until a patch is available. As a temporary workaround, disabling the handling of TIFF images may help mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2016-8331
DLA-693-1
OPENSUSE-SU-2018_1834-1
SUSE-SU-2018:1826-1
SUSE-SU-2018:1835-1
USN-3212-1
USN-3212-2
USN-3212-3

Produtos afetados

Libtiff
Suse
Ubuntu