PT-2016-5623 · None+2 · Libtiff+2
Mei Wang
·
Published
2016-10-03
·
Updated
2024-06-15
·
CVE-2016-3622
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibTIFF version 4.0.6 and earlier
Description
The issue allows remote attackers to cause a denial of service, specifically a divide-by-zero error, via a crafted TIFF image. This is due to a problem in the fpAcc function in tif predict.c in the tiff2rgba tool.
Recommendations
For LibTIFF version 4.0.6 and earlier, update to a version later than 4.0.6 to resolve the issue.
At the moment, there is no information about other specific mitigation measures for this issue.
Exploit
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libtiff
Suse
Ubuntu