CVE-2016-3622
Published: 3 October 2016
The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
tiff Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(4.0.7-1)
|
precise |
Ignored
|
|
trusty |
Released
(4.0.3-7ubuntu0.6)
|
|
upstream |
Released
(4.0.7)
|
|
wily |
Ignored
(reached end-of-life)
|
|
xenial |
Released
(4.0.6-1ubuntu0.1)
|
|
yakkety |
Released
(4.0.6-2ubuntu0.1)
|
|
zesty |
Not vulnerable
(4.0.7-1)
|
Notes
Author | Note |
---|---|
mdeslaur | "(PredictorSetup): Enforce bits-per-sample requirements of" "floating point predictor" this will not be fixed in precise/esm |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3622
- http://www.openwall.com/lists/oss-security/2016/04/07/5
- http://www.simplesystems.org/libtiff/v4.0.7.html
- https://ubuntu.com/security/notices/USN-3212-1
- NVD
- Launchpad
- Debian