PT-2016-7492 · None+2 · Libtiff+2

Published

2016-10-28

·

Updated

2022-04-19

·

CVE-2016-8331

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.0.6
Description A remote code execution issue exists in the handling of TIFF images. This is due to a type confusion vulnerability that can be triggered by a crafted TIFF document, potentially allowing remote code execution. The vulnerability can be exploited via a TIFF file delivered to the application using LibTIFF's tag extension functionality.
Recommendations For LibTIFF version 4.0.6, consider avoiding the use of TIFF files or restricting access to the tag extension functionality until a patch is available. As a temporary workaround, disabling the handling of TIFF images may help mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-8331
DLA-693-1
OPENSUSE-SU-2018_1834-1
SUSE-SU-2018:1826-1
SUSE-SU-2018:1835-1
USN-3212-1
USN-3212-2
USN-3212-3

Affected Products

Libtiff
Suse
Ubuntu