Description
Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers an out-of-bounds write.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-610-1 | tiff3 security update |
Debian DSA |
DSA-3762-1 | tiff security update |
EUVD |
EUVD-2016-4957 | Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers an out-of-bounds write. |
Ubuntu USN |
USN-3212-1 | LibTIFF vulnerabilities |
Ubuntu USN |
USN-3212-4 | LibTIFF vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:10:31.904Z
Reserved: 2016-04-01T00:00:00.000Z
Link: CVE-2016-3945
No data.
Status : Modified
Published: 2016-09-21T18:59:01.677
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-3945
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN