Junglewise Threat Intelligence

CVE-2016-5323: LibTIFF divide by zero in _TIFFFax3fillruns

CVE-2016-5323 · Severity: high · CVSS 7.5 · Published 2017-01-20

Technologies: Opensuse, Libtiff. Vendors: Opensuse, Libtiff.

Executive brief

LibTIFF is a widely used library for processing TIFF image files in various applications and operating systems. A vulnerability exists that allows a remote attacker to crash applications using this library by providing a specially crafted image file. This results in a denial of service, potentially disrupting business operations that rely on automated image processing or document management.

Technical details

A divide-by-zero vulnerability exists in the _TIFFFax3fillruns function within tif_fax3.c of libtiff. The flaw is triggered when the library processes a specially crafted TIFF image, specifically when using tools like tiffcrop that invoke Fax3 decoding routines. An attacker can exploit this by providing a malicious image file to an application linked against libtiff, leading to an arithmetic exception and subsequent process crash. This is a remote, unauthenticated attack vector requiring no user interaction beyond the application attempting to process the file. The issue was addressed in libtiff version 4.0.6 and later.

Affected products

  • LibTIFF libtiff before 4.0.6

Timeline

  • 2016-06-15: disclosed: Public disclosure on oss-security mailing list
  • 2017-01-09: advisory: Gentoo security advisory released
  • 2017-01-13: patched: Debian released security updates for jessie and sid
  • 2017-01-20: advisory: NVD publication date

References

Related threats