LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.
[
{
"id": "CVE-2016-10267-4703119c",
"deprecated": false,
"source": "https://github.com/vadz/libtiff/commit/43bc256d8ae44b92d2734a3c5bc73957a4d7c1ec",
"digest": {
"length": 347.0,
"function_hash": "85582107942879496567959941676705412335"
},
"target": {
"function": "OJPEGDecode",
"file": "libtiff/tif_ojpeg.c"
},
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2016-10267-624ff273",
"deprecated": false,
"source": "https://github.com/vadz/libtiff/commit/43bc256d8ae44b92d2734a3c5bc73957a4d7c1ec",
"digest": {
"length": 1694.0,
"function_hash": "156318966771772514769746698087866865512"
},
"target": {
"function": "OJPEGPreDecode",
"file": "libtiff/tif_ojpeg.c"
},
"signature_version": "v1",
"signature_type": "Function"
},
{
"id": "CVE-2016-10267-b313a682",
"deprecated": false,
"source": "https://github.com/vadz/libtiff/commit/43bc256d8ae44b92d2734a3c5bc73957a4d7c1ec",
"digest": {
"line_hashes": [
"322333503481229944658968606616599779722",
"218940841122844729741915087821861000700",
"78562187751908492322266681023785214381",
"219923065471346736879067525709848344957",
"6406734774835764335012954706007276335",
"201295891906060101327818799006370180049",
"36331285705548152810167182104847113308",
"165908337204619719157708677777791444343",
"242294379943244551697332372191981889879",
"313302078053050635561130110889050789540",
"5331214134672034809495324905050538132",
"214058183052038536023288415807348537313",
"76449045185817731882669222601689716625",
"260150799647038931196806821937218714874"
],
"threshold": 0.9
},
"target": {
"file": "libtiff/tif_ojpeg.c"
},
"signature_version": "v1",
"signature_type": "Line"
}
]