CVE-2016-5317: Buffer Overflow
Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5317?
CVE-2016-5317 is classified as a moderate severity vulnerability that can lead to a denial of service attack.
How do I fix CVE-2016-5317?
To fix CVE-2016-5317, update to versions 4.1.0+git191117-2~deb10u4 or later of the tiff package.
Which software is affected by CVE-2016-5317?
CVE-2016-5317 affects libtiff versions 4.0.6 and earlier, as well as specific versions of the tiff package on Debian and openSUSE.
What type of attack can CVE-2016-5317 cause?
CVE-2016-5317 can cause a denial of service by crashing the application that processes a crafted TIFF file.
How can I verify if I am running an affected version related to CVE-2016-5317?
You can verify your version of the tiff package or libtiff by checking your installed software packages against the versions mentioned in the CVE description.