LibTIFF is prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, code-execution may be possible but this has not been confirmed.
LibTIFF 4.0.7 is vulnerable; other versions may also be affected.
Information
Bugtraq ID: 97201Class: Boundary Condition Error
CVE: CVE-2016-10269
Remote: Yes
Local: No
Published: Mar 24 2017 12:00AM
Credit: Agostino Sarubbo of Gentoo.
Vulnerable: LibTIFF LibTIFF 4.0.7
Not Vulnerable:
Exploit
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
References:
- * libtiff/tif_pixarlog.c, libtiff/tif_luv.c: fix heap-based buffer (libtiff)
- LibTIFF Homepage (LibTIFF)
- libtiff: multiple heap-based buffer overflow (gentoo.org)