CVE-2016-10371: Input Validation
Last updated 24 July 2024
Other sources
The TIFFWriteDirectoryTagCheckedRational function in tifdirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10371?
CVE-2016-10371 has a severity rating that indicates it can lead to denial of service due to application crashes from crafted TIFF files.
How do I fix CVE-2016-10371?
To fix CVE-2016-10371, update LibTIFF to version 4.0.7 or later, or apply any relevant patches provided by your vendor.
What software is affected by CVE-2016-10371?
CVE-2016-10371 affects LibTIFF versions 4.0.6 and several specific versions of the tiff package in Debian.
Can CVE-2016-10371 be exploited remotely?
Yes, CVE-2016-10371 can be exploited by remote attackers using crafted TIFF files to cause denial of service.
What is the impact of CVE-2016-10371?
The impact of CVE-2016-10371 is a denial of service condition which can result in the application crashing.