CVE-2016-3658: High severity tiff vulnerability
Published Oct 3, 2016
·Updated
The TIFFWriteDirectoryTagLongLong8Array function in tifdirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable.
Affected Software
1 affected component
LibTIFF libtiff<=4.0.6
Event History
Oct 3, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3658?
CVE-2016-3658 has a severity rating that indicates it can lead to a denial of service due to an out-of-bounds read.
2
How do I fix CVE-2016-3658?
To fix CVE-2016-3658, update to LibTIFF version 4.0.7 or later where the vulnerability has been resolved.
3
What versions of LibTIFF are affected by CVE-2016-3658?
LibTIFF versions 4.0.6 and earlier are affected by CVE-2016-3658.
4
What type of vulnerability is CVE-2016-3658?
CVE-2016-3658 is a denial of service vulnerability caused by an out-of-bounds read.
5
Can CVE-2016-3658 be exploited remotely?
Yes, CVE-2016-3658 can be exploited remotely by attackers to cause a denial of service.