CVE-2016-3619
Published: 3 October 2016
The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.
Priority
CVSS 3 base score: 6.5
Notes
Author | Note |
---|---|
sbeattie | out of bounds read |
mdeslaur | upstream removed the bmp2tiff utility in 4.0.7 we will not be fixing this minor issue, marking as ignored |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3619
- http://www.openwall.com/lists/oss-security/2016/04/07/1
- NVD
- Launchpad
- Debian