CVE-2016-3186Improper Restriction of Operations within the Bounds of a Memory Buffer in Libtiff

Severity
6.2MEDIUMNVD
EPSS
0.8%
top 26.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateMay 14

Description

Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6

Affected Packages3 packages

NVDlibtiff/libtiff4.0.6
debiandebian/tiff< tiff 4.0.6-3 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-3x5j-gmvm-pgmx: Buffer overflow in the readextension function in gif2tiff2022-05-14
OSV
CVE-2016-3186: Buffer overflow in the readextension function in gif2tiff2016-04-19

📋Vendor Advisories

3
Ubuntu
LibTIFF vulnerabilities2018-03-26
Red Hat
libtiff: buffer overflow in gif2tiff2016-03-30
Debian
CVE-2016-3186: tiff - Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 all...2016

💬Community

5
Bugzilla
CVE-2016-3186 mingw-libtiff: libtiff: buffer overflow in gif2tiff [epel-7]2016-03-30
Bugzilla
CVE-2016-3186 mingw-libtiff: libtiff: buffer overflow in gif2tiff [fedora-all]2016-03-30
Bugzilla
CVE-2016-3186 libtiff: buffer overflow in gif2tiff [fedora-all]2016-03-30
Bugzilla
CVE-2016-3186 libtiff: buffer overflow in gif2tiff2016-03-21
Bugzilla
buffer overflow in gif2tiff2016-03-20