CVE-2016-5323: Divide by Zero
The TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5323?
CVE-2016-5323 is classified as a denial of service vulnerability due to a divide-by-zero error that can cause application crashes.
How do I fix CVE-2016-5323?
To mitigate CVE-2016-5323, update libtiff to version 4.0.6 or later, or apply security patches provided by the affected software vendors.
What software is affected by CVE-2016-5323?
CVE-2016-5323 affects various versions of libtiff prior to 4.0.6, as well as specific package versions in Debian and openSUSE distributions.
Can exploiting CVE-2016-5323 lead to data loss?
While CVE-2016-5323 primarily causes application crashes, it could indirectly lead to data loss if the application fails to handle data correctly during the crash.
Is CVE-2016-5323 still a threat today?
CVE-2016-5323 may still pose a threat to systems that have not been updated since the vulnerability was disclosed.