VulnerabilityModified
CVE-2016-5317
Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.
MEDIUM 6.5EPSS 1.96%
Does this matter?
Lower severity and a low EPSS score (1.96%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- libtiff/libtiff · opensuse/opensuse · opensuse project/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2016-07/msg00087.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00060.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00090.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3762
- http://www.openwall.com/lists/oss-security/2016/06/15/10Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/06/15/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/91208
- https://security.gentoo.org/glsa/201701-16
- http://lists.opensuse.org/opensuse-updates/2016-07/msg00087.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00060.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00090.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3762
- http://www.openwall.com/lists/oss-security/2016/06/15/10Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/06/15/5Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/91208
- https://security.gentoo.org/glsa/201701-16
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.