Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers an out-of-bounds write.
http://bugzilla.maptools.org/show_bug.cgi?id=2545
http://lists.opensuse.org/opensuse-updates/2016-09/msg00039.html
http://rhn.redhat.com/errata/RHSA-2016-1546.html
http://rhn.redhat.com/errata/RHSA-2016-1547.html
http://www.debian.org/security/2017/dsa-3762
http://www.openwall.com/lists/oss-security/2016/04/08/6
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/85960
Source: MITRE
Published: 2016-09-21
Updated: 2018-10-30
Type: CWE-190
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* versions up to 4.0.6 (inclusive)
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124940 | EulerOS Virtualization 3.0.1.0 : libtiff (EulerOS-SA-2019-1437) | Nessus | Huawei Local Security Checks | high |
109674 | SUSE SLES11 Security Update : tiff (SUSE-SU-2018:1179-1) | Nessus | SuSE Local Security Checks | high |
102258 | Ubuntu 12.04 LTS : tiff vulnerabilities (USN-3212-4) | Nessus | Ubuntu Local Security Checks | high |
99889 | EulerOS 2.0 SP1 : compat-libtiff3 (EulerOS-SA-2017-1044) | Nessus | Huawei Local Security Checks | high |
99888 | EulerOS 2.0 SP2 : compat-libtiff3 (EulerOS-SA-2017-1043) | Nessus | Huawei Local Security Checks | high |
99797 | EulerOS 2.0 SP1 : libtiff (EulerOS-SA-2016-1034) | Nessus | Huawei Local Security Checks | high |
97434 | Ubuntu 14.04 LTS / 16.04 LTS / 16.10 : tiff vulnerabilities (USN-3212-1) | Nessus | Ubuntu Local Security Checks | high |
96704 | Debian DLA-795-1 : tiff security update | Nessus | Debian Local Security Checks | high |
96495 | Debian DSA-3762-1 : tiff - security update | Nessus | Debian Local Security Checks | high |
96373 | GLSA-201701-16 : libTIFF: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
94067 | SUSE SLES11 Security Update : tiff (SUSE-SU-2016:2527-1) | Nessus | SuSE Local Security Checks | medium |
94062 | openSUSE Security Update : tiff (openSUSE-2016-1187) | Nessus | SuSE Local Security Checks | medium |
94039 | SUSE SLED12 / SLES12 Security Update : tiff (SUSE-SU-2016:2508-1) | Nessus | SuSE Local Security Checks | medium |
93707 | openSUSE Security Update : tiff (openSUSE-2016-1122) | Nessus | SuSE Local Security Checks | medium |
93432 | openSUSE Security Update : tiff (openSUSE-2016-1069) | Nessus | SuSE Local Security Checks | medium |
93322 | Debian DLA-610-2 : tiff3 regression update | Nessus | Debian Local Security Checks | high |
93011 | Amazon Linux AMI : libtiff (ALAS-2016-733) | Nessus | Amazon Linux Local Security Checks | high |
92720 | Scientific Linux Security Update : libtiff on SL7.x x86_64 (20160802) | Nessus | Scientific Linux Local Security Checks | high |
92698 | Scientific Linux Security Update : libtiff on SL6.x i386/x86_64 (20160802) | Nessus | Scientific Linux Local Security Checks | high |
92697 | RHEL 6 : libtiff (RHSA-2016:1547) | Nessus | Red Hat Local Security Checks | high |
92696 | RHEL 7 : libtiff (RHSA-2016:1546) | Nessus | Red Hat Local Security Checks | high |
92691 | OracleVM 3.3 / 3.4 : libtiff (OVMSA-2016-0093) | Nessus | OracleVM Local Security Checks | high |
92690 | Oracle Linux 6 : libtiff (ELSA-2016-1547) | Nessus | Oracle Linux Local Security Checks | high |
92689 | Oracle Linux 7 : libtiff (ELSA-2016-1546) | Nessus | Oracle Linux Local Security Checks | high |
92682 | CentOS 6 : libtiff (CESA-2016:1547) | Nessus | CentOS Local Security Checks | high |
92681 | CentOS 7 : libtiff (CESA-2016:1546) | Nessus | CentOS Local Security Checks | high |