First published: Fri Mar 24 2017(Updated: )
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tif_read.c:523:22.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tiff | =4.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10270 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
To fix CVE-2016-10270, upgrade to a patched version of LibTIFF that addresses this vulnerability.
The consequences of CVE-2016-10270 include potential denial of service attacks through crafted TIFF images.
CVE-2016-10270 specifically affects LibTIFF version 4.0.7.
Yes, CVE-2016-10270 can be exploited by remote attackers through the use of specially crafted TIFF images.