{"id":"CVE-2016-10270","details":"LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to \"READ of size 8\" and libtiff/tif_read.c:523:22.","modified":"2026-07-08T12:43:01.571263Z","published":"2017-03-24T19:59:00.283Z","related":["SUSE-SU-2017:1044-1","SUSE-SU-2018:1472-1","openSUSE-SU-2024:11461-1"],"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/97200"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3844"},{"type":"FIX","url":"https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/"},{"type":"FIX","url":"https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vadz/libtiff","events":[{"introduced":"b28076b056eba9d665881bab139d21b21137fd2d"},{"last_affected":"b28076b056eba9d665881bab139d21b21137fd2d"},{"fixed":"9a72a69e035ee70ff5c41541c8c61cd97990d018"}],"database_specific":{"cpe":"cpe:2.3:a:libtiff:libtiff:4.0.7:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.7"},{"last_affected":"4.0.7"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["4.0.7","Release-v4-0-7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10270.json","vanir_signatures_modified":"2026-07-08T12:43:01Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"217570062935108207213506467783707032506","length":419},"id":"CVE-2016-10270-21043118","signature_type":"Function","signature_version":"v1","source":"https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018","target":{"file":"libtiff/tif_strip.c","function":"TIFFNumberOfStrips"}},{"id":"CVE-2016-10270-438ef051","signature_type":"Line","signature_version":"v1","source":"https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018","target":{"file":"libtiff/tif_dirread.c"},"deprecated":false,"digest":{"line_hashes":["227979037930115295549200606344797044780","304064853075978727773745147678512944439","247178991344022167237135730424070535552","281215183600724245730294442974530095132","305164763526171681635348485961970663495","178073106303980633009179021628806583257","124692354437170973845498308911739901343","114172573406440844168977052736038871039","216187158007511905708691702014797602141","2879496617748360527738794824120368194","104995666070552702337610097727930891288","115243487901340338471005043152426292490","139147012495639512798477566459269828020","105464633538825495977824827820924822994","107723553272322545637638858690250870762","290931200856179411197202820462678260933","53478847736288984055319536672304171640","47816606002615624330881726773444678337","41175390837799653466983724778626736192","71200253766754932186272388276437218414","203193398437237192607582729440697709897","70722196196013249240151454962309002082","326510936351076789053991261527542020492","272834617046870365591399382044184695558","181871094969194701087817509287023198281","254431987391002376872065047137279717069","269526769066251921302003633010157440788","202417575990367002590428723634683427130","302339418109204909993807813573261863499"],"threshold":0.9}},{"target":{"file":"libtiff/tif_dirread.c","function":"ChopUpSingleUncompressedStrip"},"deprecated":false,"digest":{"function_hash":"202781527579831873861974969934754624663","length":1623},"id":"CVE-2016-10270-b0b62bfc","signature_type":"Function","signature_version":"v1","source":"https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["251259821279157970787903007296993735349","216789091117803774823384587008877918412","335551065774136630098571473824439443675","89261644350307141058375409406669172333","102137725275466551305934319509417008195"]},"id":"CVE-2016-10270-c10031cd","signature_type":"Line","signature_version":"v1","source":"https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018","target":{"file":"libtiff/tif_strip.c"}}]}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/libtiff/libtiff","events":[{"introduced":"884f973652b8b020e533b1e340da3ef4bcd1d925"},{"last_affected":"884f973652b8b020e533b1e340da3ef4bcd1d925"}],"database_specific":{"cpe":"cpe:2.3:a:libtiff:libtiff:4.0.7:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.7"},{"last_affected":"4.0.7"}],"source":"CPE_STRING"}}],"versions":["4.0.7","v4.0.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10270.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}