CVE-2016-3631: High severity tiff vulnerability
Published Oct 3, 2016
·Updated
The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the bytecounts[] array variable.
Affected Software
1 affected component
LibTIFF libtiff<=4.0.6
Event History
Oct 3, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3631?
CVE-2016-3631 is classified as a denial of service vulnerability due to out-of-bounds reads that affect LibTIFF versions 4.0.6 and earlier.
2
How do I fix CVE-2016-3631?
To fix CVE-2016-3631, update LibTIFF to version 4.0.7 or later, which addresses the vulnerability.
3
What software is affected by CVE-2016-3631?
CVE-2016-3631 affects LibTIFF version 4.0.6 and earlier.
4
Can CVE-2016-3631 be exploited remotely?
Yes, CVE-2016-3631 can be exploited remotely by attackers to cause a denial of service.
5
What are the implications of CVE-2016-3631 for users?
Users running affected versions of LibTIFF may experience service outages due to the denial of service caused by CVE-2016-3631.