PT-2017-7836 · Libtiff+2 · Libtiff+2
Agostino Sarubbo
·
Published
2017-03-24
·
Updated
2024-06-15
·
CVE-2016-10266
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LibTIFF version 4.0.7
Description
The issue allows remote attackers to cause a denial of service, resulting in a divide-by-zero error and application crash, via a crafted TIFF image. This is related to the tif read.c file.
Recommendations
For LibTIFF version 4.0.7, consider updating to a newer version that contains a fix for this issue, as no specific workaround is provided for this version.
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libtiff
Suse
Ubuntu