Severity
7.8HIGH
EPSS
0.2%
top 63.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateMay 14

Description

Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers an out-of-bounds write.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlibtiff/libtiff4.0.6
Debiantiff< 4.0.7-1+3
NVDoracle/vm_server3.3, 3.4+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wc43-4wvj-c97c: Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 42022-05-14
CVEList
CVE-2016-3945: Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 42016-09-21
OSV
CVE-2016-3945: Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 42016-09-21

📋Vendor Advisories

4
Ubuntu
LibTIFF vulnerabilities2017-08-07
Ubuntu
LibTIFF vulnerabilities2017-02-27
Red Hat
libtiff: out-of-bounds write in the tiff2rgba tool2016-04-08
Debian
CVE-2016-3945: tiff - Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions...2016

💬Community

1
Bugzilla
CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool2016-04-08
CVE-2016-3945 (HIGH CVSS 7.8) | Multiple integer overflows in the ( | cvebase.io