CVE-2016-10093: Buffer Overflow
Integer overflow in tools/tiffcp.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5 and 4.0.6 allows remote attackers to have unspecified impact via a crafted image, which triggers a heap-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10093?
CVE-2016-10093 is classified with a moderate severity due to the potential impact on systems processing crafted TIFF images.
How do I fix CVE-2016-10093?
To resolve CVE-2016-10093, upgrade to LibTIFF version 4.1.0 or later, as these versions have addressed this vulnerability.
What software is affected by CVE-2016-10093?
CVE-2016-10093 affects LibTIFF versions 4.0.7, 3.9.3 through 3.9.7, and 4.0.0 alpha and beta versions.
Who is impacted by CVE-2016-10093?
Users and applications utilizing vulnerable versions of LibTIFF for processing images are at risk from CVE-2016-10093.
What kind of attack does CVE-2016-10093 allow?
CVE-2016-10093 allows remote attackers to trigger a heap-based integer overflow via specially crafted TIFF images.