Stack-based buffer overflow in LibTIFF - CVE-2016-5318
Published: April 3, 2018
Vulnerability identifier: #VU11493
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5318
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker can cause DoS condition on the target system.
The weakness exists in the _TIFFVGetField function due to stack-based buffer overflow. A remote attacker can submit a specially crafted tiff file and cause the service to crash.
The weakness exists in the _TIFFVGetField function due to stack-based buffer overflow. A remote attacker can submit a specially crafted tiff file and cause the service to crash.
Affected software
LibTIFF
Slackware Linux
Dynamic System Analysis (DSA) Preboot
libtiff
Slackware Linux
Dynamic System Analysis (DSA) Preboot
libtiff
How to mitigate CVE-2016-5318
Install update from vendor's website.
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
libtiff - update to 4.0.9
libtiff - update to 4.0.9