Back to search
CVE-2016-3945
Published: Sep 21, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers an out-of-bounds write.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20160408 CVE-2016-3945 libtiff: Out-of-bounds Write in the tiff2rgba tool
mailing-list
x_refsource_MLIST
RHSA-2016:1547
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1325093
x_refsource_CONFIRM
GLSA-201701-16
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2016:2275
vendor-advisory
x_refsource_SUSE
RHSA-2016:1546
vendor-advisory
x_refsource_REDHAT
85960
vdb-entry
x_refsource_BID
DSA-3762
vendor-advisory
x_refsource_DEBIAN
http://bugzilla.maptools.org/show_bug.cgi?id=2545
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now