CVE-2016-5319: Buffer Overflow
Published Jan 20, 2017
·Updated
Heap-based buffer overflow in tifpackbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.
Affected Software
1 affected component
LibTIFF libtiff<=4.0.6
Event History
Jan 20, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5319?
CVE-2016-5319 has a medium severity rating due to the potential for application crashes caused by crafted BMP files.
2
How do I fix CVE-2016-5319?
To mitigate CVE-2016-5319, upgrade to libtiff version 4.0.6 or later.
3
What does CVE-2016-5319 affect?
CVE-2016-5319 affects libtiff versions up to and including 4.0.6.
4
What type of vulnerability is CVE-2016-5319?
CVE-2016-5319 is a heap-based buffer overflow vulnerability.
5
How can attackers exploit CVE-2016-5319?
Attackers can exploit CVE-2016-5319 by sending crafted BMP files that cause the application to crash.