CVE-2016-10267: Divide by Zero
Published Mar 24, 2017
·Updated
Last updated 24 July 2024
Other sources
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tifojpeg.c:816:8.
Affected Software
2 affected componentsFixes available
LibTIFF libtiff=4.0.7
debian/tiff
4.2.0-1+deb11u54.2.0-1+deb11u64.5.0-6+deb12u24.5.0-6+deb12u14.7.0-3
Remediation
Event History
Mar 24, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Aug 5, 2024
Data Sourced
via Launchpad·05:51 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·05:58 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-10267?
CVE-2016-10267 is considered a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2016-10267?
To fix CVE-2016-10267, update the vulnerable LibTIFF package to versions 4.2.0-1+deb11u5 or later.
3
Which software versions are affected by CVE-2016-10267?
CVE-2016-10267 affects LibTIFF version 4.0.7 and any applications utilizing that version without the proper updates.
4
What type of attack does CVE-2016-10267 facilitate?
CVE-2016-10267 allows remote attackers to launch a denial of service attack through crafted TIFF images.
5
What is the impact of CVE-2016-10267 on applications?
The impact of CVE-2016-10267 on applications is an application crash due to a divide-by-zero error.