CVE-2016-5102Improper Input Validation in Libtiff

Severity
5.5MEDIUMNVD
EPSS
0.6%
top 30.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 6
Latest updateMay 14

Description

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDlibtiff/libtiff4.0.6
debiandebian/tiff< tiff 4.0.6-3 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-fj3q-x7c6-x788: Buffer overflow in the readgifimage function in gif2tiff2022-05-14
OSV
CVE-2016-5102: Buffer overflow in the readgifimage function in gif2tiff2017-02-06

📋Vendor Advisories

3
Ubuntu
LibTIFF vulnerabilities2018-03-26
Red Hat
libtiff: Buffer overflow in readgifimage()2016-05-30
Debian
CVE-2016-5102: tiff - Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool ...2016

💬Community

5
Bugzilla
CVE-2016-5102 libtiff: Buffer overflow in readgifimage() [fedora-all]2016-06-07
Bugzilla
CVE-2016-5102 mingw-libtiff: libtiff: Buffer overflow in readgifimage() [fedora-all]2016-06-07
Bugzilla
CVE-2016-5102 libtiff: Buffer overflow in readgifimage()2016-06-07
Bugzilla
CVE-2016-5102 mingw-libtiff: libtiff: Buffer overflow in readgifimage() [epel-7]2016-06-07
Bugzilla
CVE-2016-3186 libtiff: buffer overflow in gif2tiff2016-03-21