CVE-2016-3622: Divide by Zero
Published Oct 3, 2016
·Updated
The fpAcc function in tifpredict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.0.6
Event History
Oct 3, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3622?
CVE-2016-3622 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2016-3622?
To fix CVE-2016-3622, upgrade to LibTIFF version 4.1.0+git191117-2~deb10u4 or later.
3
Who is affected by CVE-2016-3622?
CVE-2016-3622 affects users of LibTIFF versions 4.0.6 and earlier.
4
What exploit does CVE-2016-3622 represent?
CVE-2016-3622 allows remote attackers to exploit a divide-by-zero error in tiff2rgba.
5
What software is involved in CVE-2016-3622?
CVE-2016-3622 is associated with the tiff2rgba tool in the LibTIFF library.