CVE-2016-3634: High severity tiff vulnerability
Published Oct 3, 2016
·Updated
The tagCompare function in tifdirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to fieldtag matching.
Affected Software
1 affected component
LibTIFF libtiff<=4.0.6
Event History
Oct 3, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3634?
CVE-2016-3634 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2016-3634?
To fix CVE-2016-3634, update LibTIFF to version 4.0.7 or later.
3
What types of attacks are possible with CVE-2016-3634?
CVE-2016-3634 can be exploited by remote attackers to trigger an out-of-bounds read, leading to a denial of service.
4
Which versions of LibTIFF are affected by CVE-2016-3634?
LibTIFF versions 4.0.6 and earlier are affected by CVE-2016-3634.
5
How can I determine if I am affected by CVE-2016-3634?
Check if your application uses LibTIFF version 4.0.6 or earlier to determine if you are affected by CVE-2016-3634.