Out-of-bounds write in LibTIFF - CVE-2016-3632
Published: July 1, 2016 / Updated: June 29, 2018
Vulnerability identifier: #VU3802
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3632
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code.
The weakness exists in the _TIFFVGetField function in tif_dirinfo.c due to out-of-bounds write. A remote attacker can supply a specially crafted TIFF image and cause the service to crash or execute arbitrary code with elevated privileges.
Affected software
LibTIFF
tiff (Alpine package)
openSUSE Leap
Dynamic System Analysis (DSA) Preboot
tiff (Alpine package)
openSUSE Leap
Dynamic System Analysis (DSA) Preboot
How to mitigate CVE-2016-3632
Install update from vendor's website.
tiff (Alpine package) - update to 4.0.6-r2
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65