CVE Vulnerabilities

CVE-2016-8331

Published: Oct 28, 2016 | Modified: Apr 19, 2022
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFFs tag extension functionality.

Affected Software

Name Vendor Start Version End Version
Libtiff Libtiff 4.0.6 (including) 4.0.6 (including)
Tiff Ubuntu precise *
Tiff Ubuntu trusty *
Tiff Ubuntu upstream *
Tiff Ubuntu vivid/stable-phone-overlay *
Tiff Ubuntu wily *
Tiff Ubuntu xenial *
Tiff Ubuntu yakkety *

References