High severity7.0NVD Advisory· Published Jan 6, 2017· Updated May 6, 2026
CVE-2016-5652
CVE-2016-5652
Description
An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code execution. Vulnerability can be triggered via a saved TIFF file delivered by other means.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.talosintelligence.com/reports/TALOS-2016-0187/nvdExploitTechnical DescriptionThird Party AdvisoryVDB Entry
- rhn.redhat.com/errata/RHSA-2017-0225.htmlnvd
- www.debian.org/security/2017/dsa-3762nvd
- www.securityfocus.com/bid/93902nvd
- security.gentoo.org/glsa/201701-16nvd
News mentions
0No linked articles in our index yet.