CVE-2016-6223
Gentoo Linux Security Advisory 201701-16
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.
Las funciones TIFFReadRawStrip1 y TIFFReadRawTile1 en tif_read.c en libtiff en versiones anteriores a 4.0.7 permite a atacantes remotos provocar una denegación de servicio (caída) o posiblemente obtener información sensible a través de un índice negativo en un búfer de contenido de archivo.
It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote attacker could crash the application, leading to a denial of service, or possibly execute arbitrary code with user privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-07-14 CVE Reserved
- 2017-01-09 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/07/13/3 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2016/07/14/4 | Mailing List |
|
http://www.securityfocus.com/bid/91741 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://libtiff.maptools.org/v4.0.7.html | 2017-11-04 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3762 | 2017-11-04 | |
https://security.gentoo.org/glsa/201701-16 | 2017-11-04 |