Back

HIGH

libtiff: Heap-buffer overflow in tools/tiffcp via crafted BitsPerSample value

Published Jan 12, 2017

Description

LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.

Affected products

Remediation

Red Hat statement

This is a heap-based buffer overflow in the tiffcp utility of libtiff. A specially-crafted image when processed via the tiffcp binary, could cause it to crash or execute arbitrary code with the permissions of the user running the utility.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 12, 2017
Updated Mar 2, 2026
Reserved Jan 9, 2017
CISA Vulnrichment
Updated Oct 10, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 12, 2017