CVE Vulnerabilities

CVE-2016-8331

Published: Oct 28, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFFs tag extension functionality.

Affected Software

NameVendorStart VersionEnd Version
LibtiffLibtiff4.0.6 (including)4.0.6 (including)
TiffUbuntuesm-infra-legacy/trusty*
TiffUbuntuesm-infra/xenial*
TiffUbuntuprecise*
TiffUbuntutrusty*
TiffUbuntutrusty/esm*
TiffUbuntuupstream*
TiffUbuntuvivid/stable-phone-overlay*
TiffUbuntuwily*
TiffUbuntuxenial*
TiffUbuntuyakkety*

References