CVE-2016-6223: Critical severity LibTIFF libtiff vulnerability
Published Jan 23, 2017
·Updated
The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tifread.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.
Affected Software
2 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff<=4.0.6
Remediation
Patch Available
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6223?
CVE-2016-6223 is classified as a denial of service vulnerability that can cause application crashes.
2
How do I fix CVE-2016-6223?
To fix CVE-2016-6223, update the libtiff library to version 4.0.7 or later.
3
What software is affected by CVE-2016-6223?
CVE-2016-6223 affects libtiff versions prior to 4.0.7.
4
Can CVE-2016-6223 lead to sensitive information disclosure?
Yes, CVE-2016-6223 may allow attackers to obtain sensitive information indirectly through application crashes.
5
Is there a known exploit for CVE-2016-6223?
While not widely reported, CVE-2016-6223's nature suggests it could be exploited to trigger denial of service conditions.