CVE-2016-3621: High severity tiff vulnerability
Published Oct 3, 2016
·Updated
The LZWEncode function in tiflzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.
Affected Software
1 affected component
LibTIFF libtiff<=4.0.6
Event History
Oct 3, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3621?
CVE-2016-3621 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-3621?
To fix CVE-2016-3621, update LibTIFF to version 4.0.7 or later.
3
What software is affected by CVE-2016-3621?
CVE-2016-3621 affects LibTIFF versions 4.0.6 and earlier.
4
What type of attack is described in CVE-2016-3621?
CVE-2016-3621 describes a remote denial of service attack due to a buffer over-read.
5
Can CVE-2016-3621 be exploited through BMP images?
Yes, CVE-2016-3621 can be exploited by sending a crafted BMP image to the bmp2tiff tool with the '-c lzw' option.