CVE-2016-10092: Buffer Overflow
Heap-based buffer overflow in the readContigStripsIntoBuffer function in tifunix.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5 and 4.0.6 allows remote attackers to have unspecified impact via a crafted image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10092?
CVE-2016-10092 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2016-10092?
To fix CVE-2016-10092, update to a patched version of LibTIFF, specifically version 4.1.0 or later.
What impact does CVE-2016-10092 have on my system?
CVE-2016-10092 can allow remote attackers to exploit a heap-based buffer overflow, leading to possible arbitrary code execution.
Which versions of LibTIFF are affected by CVE-2016-10092?
Versions of LibTIFF from 4.0.7 to 4.0.6, among others, are affected by CVE-2016-10092.
Is LibTIFF used in any common applications that may be vulnerable due to CVE-2016-10092?
Yes, LibTIFF is commonly used in image processing applications, making them potentially vulnerable if they use affected versions.