CVE-2016-8331 PUBLISHED

An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

EPSS 6.22% · 90.8th percentile

Risk Scores

EPSS Score
6.22%
90.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTStiff0, 4.0.3-12.3ubuntu2, 4.0.5-1
Ubuntu:14.04:LTStiff4.0.3-6ubuntu1, 4.0.3-7, 4.0.3-7ubuntu0.1

Timeline

References

Open in Interactive Console →