CVE-2016-10268: Integer Underflow
Last updated 24 July 2024
Other sources
tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based buffer under-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 78490" and libtiff/tifunix.c:115:23.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10268?
CVE-2016-10268 has a moderate severity level due to the potential for denial of service and heap-based buffer issues.
How do I fix CVE-2016-10268?
To fix CVE-2016-10268, update to a patched version of the libtiff package, specifically versions later than 4.0.7.
What impact does CVE-2016-10268 have on systems?
CVE-2016-10268 may lead to a denial of service condition by causing integer underflow and heap-based buffer under-reads when processing crafted TIFF images.
Which software versions are affected by CVE-2016-10268?
CVE-2016-10268 affects LibTIFF version 4.0.7 and potentially earlier versions.
Is there a specific Debian package affected by CVE-2016-10268?
Yes, the Debian tiff package versions up to 4.0.7 are affected by CVE-2016-10268.