CVE-2016-10270: High severity tiff vulnerability
Published Mar 24, 2017
·Updated
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tifread.c:523:22.
Affected Software
1 affected component
LibTIFF libtiff=4.0.7
Remediation
Event History
Mar 24, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10270?
CVE-2016-10270 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2016-10270?
To fix CVE-2016-10270, upgrade to a patched version of LibTIFF that addresses this vulnerability.
3
What are the consequences of CVE-2016-10270?
The consequences of CVE-2016-10270 include potential denial of service attacks through crafted TIFF images.
4
Which versions of LibTIFF are affected by CVE-2016-10270?
CVE-2016-10270 specifically affects LibTIFF version 4.0.7.
5
Is CVE-2016-10270 exploitable by remote attackers?
Yes, CVE-2016-10270 can be exploited by remote attackers through the use of specially crafted TIFF images.