CVE-2016-3186: Buffer Overflow
A buffer overflow vulnerability was reported in libtiff library, in gif2tiff component. A maliciously crafted file could cause the application to crash.
Original bug report with reproducer:
https://bugzilla.redhat.com/showbug.cgi?id=1319503
Other sources
Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3186?
CVE-2016-3186 has a high severity rating due to its potential to cause application crashes.
How do I fix CVE-2016-3186?
To fix CVE-2016-3186, upgrade to the patched versions of the libtiff library as specified in security advisories.
Which versions of libtiff are affected by CVE-2016-3186?
CVE-2016-3186 affects libtiff versions prior to the patches provided in versions such as 4.2.0-1+deb11u5 and 4.5.1+git230720-5.
What components are involved in CVE-2016-3186?
CVE-2016-3186 involves the gif2tiff component of the libtiff library.
Can CVE-2016-3186 be exploited remotely?
Yes, CVE-2016-3186 can potentially be exploited remotely by sending a maliciously crafted TIFF file to the affected application.