CVE-2016-3625Out-of-bounds Read in Tiff

CWE-125Out-of-bounds Read6 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.6%
top 29.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 3
Latest updateMay 14

Description

tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.6
debiandebian/tiff< tiff 4.0.3-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-f7jp-mc4w-xqc7: tif_read2022-05-14
OSV
CVE-2016-3625: tif_read2016-10-03

📋Vendor Advisories

2
Red Hat
libtiff: out of bounds read in the tiff2bw tool2016-04-08
Debian
CVE-2016-3625: tiff - tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attack...2016

💬Community

1
Bugzilla
CVE-2016-3625 libtiff: out of bounds read in the tiff2bw tool2016-04-08