CVE-2016-3625: Medium severity tiff vulnerability
Published Oct 3, 2016
·Updated
tifread.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
Affected Software
1 affected component
LibTIFF libtiff<=4.0.6
Event History
Oct 3, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3625?
CVE-2016-3625 has been classified as a denial of service vulnerability, which can lead to application crashes due to an out-of-bounds read.
2
How do I fix CVE-2016-3625?
To fix CVE-2016-3625, upgrade LibTIFF to version 4.0.7 or later, which addresses this vulnerability.
3
Which versions of LibTIFF are affected by CVE-2016-3625?
CVE-2016-3625 affects LibTIFF versions 4.0.6 and earlier.
4
Can CVE-2016-3625 be exploited remotely?
Yes, CVE-2016-3625 can be exploited remotely by supplying a crafted TIFF image that triggers the vulnerability.
5
What component of LibTIFF is affected by CVE-2016-3625?
The vulnerability in CVE-2016-3625 specifically affects the tif_read.c component of the tiff2bw tool.