CVE-2016-6223 PUBLISHED

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

EPSS 1.24% · 79.1th percentile

Risk Scores

EPSS Score
1.24%
79.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTStiff0, 4.0.2-4ubuntu3, 4.0.3-5ubuntu1
Ubuntu:16.04:LTStiff0, 4.0.3-12.3ubuntu2, 4.0.5-1

Timeline

References

Open in Interactive Console →