CVE-2016-5321: Buffer Overflow
Published Jan 20, 2017
·Updated
The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff image.
Affected Software
3 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
openSUSE openSUSE=13.1
LibTIFF libtiff<=4.0.6
Event History
Jan 20, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5321?
CVE-2016-5321 is classified as a denial of service vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2016-5321?
To resolve CVE-2016-5321, upgrade to a version of libtiff that is 4.1.0 or later, such as 4.1.0+git191117-2~deb10u4.
3
Which versions of libtiff are affected by CVE-2016-5321?
CVE-2016-5321 affects libtiff versions 4.0.6 and earlier.
4
Can CVE-2016-5321 be exploited remotely?
Yes, CVE-2016-5321 can be exploited by an attacker using a crafted TIFF image to trigger the vulnerability.
5
What platforms are impacted by CVE-2016-5321?
CVE-2016-5321 impacts platforms using libtiff versions up to 4.0.6, including Debian and openSUSE.