CVE-2016-5102: Buffer Overflow
A vulnerability was found in libtiff. A maliciously crafted file could cause the application to crash via buffer overflow in gif2tiff tool.
Upstream bug:
http://bugzilla.maptools.org/showbug.cgi?id=2552
Other sources
Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5102?
CVE-2016-5102 is classified as a medium severity vulnerability due to the potential for application crashes and exploitation via buffer overflow.
How do I fix CVE-2016-5102?
To fix CVE-2016-5102, update the libtiff package to a version that is not vulnerable, specifically versions 4.2.0-1+deb11u6 and later or 4.5.1+git230720-5.
Which software is affected by CVE-2016-5102?
CVE-2016-5102 affects the libtiff library and the gif2tiff tool within specific versions of the tiff package.
What type of attack does CVE-2016-5102 enable?
CVE-2016-5102 enables a buffer overflow attack that can lead to application crashes and potential remote code execution.
Are there any workarounds for CVE-2016-5102?
Currently, the best way to mitigate CVE-2016-5102 is to avoid processing untrusted TIFF files and upgrade the affected software.