← back
CVE-2016-5652

CVE-2016-5652

EPSS 4.3%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 4.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
06 Jan 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code execution. Vulnerability can be triggered via a saved TIFF file delivered by other means.
Affected products
LibTiff · LibTiff

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →