CVE-2016-5323

HIGH

Libtiff < 4.0.6 - Divide By Zero

Title source: rule

Description

The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.

Scores

CVSS v3 7.5
EPSS 0.0111
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-369
Status draft

Affected Products (2)

libtiff/libtiff < 4.0.6
opensuse/opensuse

Timeline

Published Jan 20, 2017
Tracked Since Feb 18, 2026