Buffer overflow in LibTIFF - CVE-2016-3186

 

Buffer overflow in LibTIFF - CVE-2016-3186

Published: April 3, 2018


Vulnerability identifier: #VU11491
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3186
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker can cause DoS condition on the target system.

The weakness exists in the gif2tiff.c due to buffer overflow. A remote attacker can submit a specially crafted GIF file and cause the service to crash.

Affected software

LibTIFF
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
tiff (Alpine package)
Data Computing Appliance (DCA)

How to mitigate CVE-2016-3186

Install update from vendor's website.

tiff (Alpine package) - update to 4.0.7-r0
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins