PT-2016-5770 · Libtiff+5 · Libtiff+5
Andrej Nemec
·
Published
2016-08-02
·
Updated
2024-06-15
·
CVE-2016-3945
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibTIFF versions 4.0.6 and earlier
Description
The issue is related to multiple integer overflows in the
cvt by strip and cvt by tile functions in the tiff2rgba tool. When the -b mode is enabled, remote attackers can cause a denial of service or execute arbitrary code via a crafted TIFF image, triggering an out-of-bounds write.Recommendations
For LibTIFF versions 4.0.6 and earlier, consider disabling the tiff2rgba tool or restricting its use until a patch is available. As a temporary workaround, avoid using the -b mode in the tiff2rgba tool to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Integer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Libtiff
Red Hat
Suse
Ubuntu