#VU32168 Out-of-bounds read in LibTIFF - CVE-2016-3621
Published: October 3, 2016 / Updated: July 28, 2020
LibTIFF
LibTIFF
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used,. A remote attacker can perform a denial of service (buffer over-read) via a crafted BMP image.