CVE-2016-10371Improper Input Validation in Tiff

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 34.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 10
Latest updateMay 14

Description

The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.6
debiandebian/tiff< tiff 4.0.7-7 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-vpfx-5xjm-5r77: The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite2022-05-14
OSV
CVE-2016-10371: The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite2017-05-10

📋Vendor Advisories

3
Ubuntu
LibTIFF vulnerabilities2018-03-20
Red Hat
libtiff: Assertion failure in TIFFWriteDirectoryTagCheckedRational2016-02-05
Debian
CVE-2016-10371: tiff - The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4...2016

💬Community

4
Bugzilla
CVE-2016-10371 libtiff: Assertion failure in TIFFWriteDirectoryTagCheckedRational [fedora-all]2017-05-10
Bugzilla
CVE-2016-10371 mingw-libtiff: libtiff: Assertion failure in TIFFWriteDirectoryTagCheckedRational [epel-7]2017-05-10
Bugzilla
CVE-2016-10371 libtiff: Assertion failure in TIFFWriteDirectoryTagCheckedRational2017-05-10
Bugzilla
CVE-2016-10371 mingw-libtiff: libtiff: Assertion failure in TIFFWriteDirectoryTagCheckedRational [fedora-all]2017-05-10