CVE-2016-8331
An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.59% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- libtiff/libtiff
- Source
- talos-cna@cisco.com
References
- http://www.securityfocus.com/bid/93898Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0190/Exploit, Technical Description, Third Party Advisory
- https://security.gentoo.org/glsa/201701-16
- http://www.securityfocus.com/bid/93898Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0190/Exploit, Technical Description, Third Party Advisory
- https://security.gentoo.org/glsa/201701-16
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.