The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.
http://rhn.redhat.com/errata/RHSA-2016-1546.html
http://rhn.redhat.com/errata/RHSA-2016-1547.html
http://www.debian.org/security/2016/dsa-3467
http://www.openwall.com/lists/oss-security/2015/12/25/1
http://www.openwall.com/lists/oss-security/2015/12/26/1
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/79718
http://www.securitytracker.com/id/1035508
Source: MITRE
Published: 2016-04-13
Updated: 2018-01-05
Type: CWE-119
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.8
Severity: MEDIUM
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
99889 | EulerOS 2.0 SP1 : compat-libtiff3 (EulerOS-SA-2017-1044) | Nessus | Huawei Local Security Checks | high |
99888 | EulerOS 2.0 SP2 : compat-libtiff3 (EulerOS-SA-2017-1043) | Nessus | Huawei Local Security Checks | high |
99797 | EulerOS 2.0 SP1 : libtiff (EulerOS-SA-2016-1034) | Nessus | Huawei Local Security Checks | high |
99249 | Slackware 14.2 / current : libtiff (SSA:2017-098-01) | Nessus | Slackware Local Security Checks | medium |
96373 | GLSA-201701-16 : libTIFF: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
95649 | openSUSE Security Update : tiff (openSUSE-2016-1425) | Nessus | SuSE Local Security Checks | high |
94647 | F5 Networks BIG-IP : Multiple LibTIFF vulnerabilities (K35155453) | Nessus | F5 Networks Local Security Checks | medium |
93322 | Debian DLA-610-2 : tiff3 regression update | Nessus | Debian Local Security Checks | high |
93012 | Amazon Linux AMI : compat-libtiff3 (ALAS-2016-734) | Nessus | Amazon Linux Local Security Checks | medium |
93011 | Amazon Linux AMI : libtiff (ALAS-2016-733) | Nessus | Amazon Linux Local Security Checks | high |
92720 | Scientific Linux Security Update : libtiff on SL7.x x86_64 (20160802) | Nessus | Scientific Linux Local Security Checks | high |
92698 | Scientific Linux Security Update : libtiff on SL6.x i386/x86_64 (20160802) | Nessus | Scientific Linux Local Security Checks | high |
92697 | RHEL 6 : libtiff (RHSA-2016:1547) | Nessus | Red Hat Local Security Checks | high |
92696 | RHEL 7 : libtiff (RHSA-2016:1546) | Nessus | Red Hat Local Security Checks | high |
92691 | OracleVM 3.3 / 3.4 : libtiff (OVMSA-2016-0093) | Nessus | OracleVM Local Security Checks | high |
92690 | Oracle Linux 6 : libtiff (ELSA-2016-1547) | Nessus | Oracle Linux Local Security Checks | high |
92689 | Oracle Linux 7 : libtiff (ELSA-2016-1546) | Nessus | Oracle Linux Local Security Checks | high |
92682 | CentOS 6 : libtiff (CESA-2016:1547) | Nessus | CentOS Local Security Checks | high |
92681 | CentOS 7 : libtiff (CESA-2016:1546) | Nessus | CentOS Local Security Checks | high |
90147 | Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : tiff vulnerabilities (USN-2939-1) | Nessus | Ubuntu Local Security Checks | medium |
88601 | Debian DSA-3467-1 : tiff - security update | Nessus | Debian Local Security Checks | medium |
88387 | Debian DLA-402-1 : tiff security update | Nessus | Debian Local Security Checks | medium |
87748 | FreeBSD : tiff -- out-of-bounds read in CIE Lab image format (b65e4914-b3bc-11e5-8255-5453ed2e2b49) | Nessus | FreeBSD Local Security Checks | medium |