tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
http://bugzilla.maptools.org/show_bug.cgi?id=2522
http://lists.opensuse.org/opensuse-updates/2016-02/msg00058.html
http://lists.opensuse.org/opensuse-updates/2016-02/msg00064.html
http://rhn.redhat.com/errata/RHSA-2016-1546.html
http://rhn.redhat.com/errata/RHSA-2016-1547.html
http://www.debian.org/security/2016/dsa-3467
http://www.openwall.com/lists/oss-security/2016/01/24/3
http://www.openwall.com/lists/oss-security/2016/01/24/7
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/81730
Source: MITRE
Published: 2016-02-01
Updated: 2019-12-31
Type: CWE-125
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
99797 | EulerOS 2.0 SP1 : libtiff (EulerOS-SA-2016-1034) | Nessus | Huawei Local Security Checks | high |
99107 | Debian DLA-880-1 : tiff3 security update | Nessus | Debian Local Security Checks | high |
96373 | GLSA-201701-16 : libTIFF: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
94647 | F5 Networks BIG-IP : Multiple LibTIFF vulnerabilities (K35155453) | Nessus | F5 Networks Local Security Checks | medium |
93707 | openSUSE Security Update : tiff (openSUSE-2016-1122) | Nessus | SuSE Local Security Checks | medium |
93585 | openSUSE Security Update : tiff (openSUSE-2016-1089) | Nessus | SuSE Local Security Checks | medium |
93439 | SUSE SLED12 / SLES12 Security Update : tiff (SUSE-SU-2016:2271-1) | Nessus | SuSE Local Security Checks | medium |
93012 | Amazon Linux AMI : compat-libtiff3 (ALAS-2016-734) | Nessus | Amazon Linux Local Security Checks | medium |
93011 | Amazon Linux AMI : libtiff (ALAS-2016-733) | Nessus | Amazon Linux Local Security Checks | high |
92720 | Scientific Linux Security Update : libtiff on SL7.x x86_64 (20160802) | Nessus | Scientific Linux Local Security Checks | high |
92698 | Scientific Linux Security Update : libtiff on SL6.x i386/x86_64 (20160802) | Nessus | Scientific Linux Local Security Checks | high |
92697 | RHEL 6 : libtiff (RHSA-2016:1547) | Nessus | Red Hat Local Security Checks | high |
92696 | RHEL 7 : libtiff (RHSA-2016:1546) | Nessus | Red Hat Local Security Checks | high |
92690 | Oracle Linux 6 : libtiff (ELSA-2016-1547) | Nessus | Oracle Linux Local Security Checks | high |
92689 | Oracle Linux 7 : libtiff (ELSA-2016-1546) | Nessus | Oracle Linux Local Security Checks | high |
92682 | CentOS 6 : libtiff (CESA-2016:1547) | Nessus | CentOS Local Security Checks | high |
92681 | CentOS 7 : libtiff (CESA-2016:1546) | Nessus | CentOS Local Security Checks | high |
90147 | Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : tiff vulnerabilities (USN-2939-1) | Nessus | Ubuntu Local Security Checks | medium |
88704 | openSUSE Security Update : tiff (openSUSE-2016-184) | Nessus | SuSE Local Security Checks | medium |
88685 | openSUSE Security Update : tiff (openSUSE-2016-179) | Nessus | SuSE Local Security Checks | medium |
88677 | SUSE SLED11 / SLES11 Security Update : tiff (SUSE-SU-2016:0353-1) | Nessus | SuSE Local Security Checks | high |
88601 | Debian DSA-3467-1 : tiff - security update | Nessus | Debian Local Security Checks | medium |
88491 | Debian DLA-405-1 : tiff security update | Nessus | Debian Local Security Checks | medium |