tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based buffer under-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 78490" and libtiff/tif_unix.c:115:23.
[
{
"id": "CVE-2016-10268-1bab0a91",
"source": "https://github.com/vadz/libtiff/commit/5397a417e61258c69209904e652a1f409ec3b9df",
"signature_type": "Line",
"target": {
"file": "tools/tiffcp.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"337903007202317363096527500964560745505",
"102090245260380114060256225456485480944",
"118198120801623005113575898576944486927",
"285537326060995222428606247736224586344"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"id": "CVE-2016-10268-245cba23",
"source": "https://github.com/vadz/libtiff/commit/5397a417e61258c69209904e652a1f409ec3b9df",
"signature_type": "Function",
"target": {
"file": "tools/tiffcp.c",
"function": "DECLAREcpFunc"
},
"deprecated": false,
"digest": {
"length": 905.0,
"function_hash": "273180704437484204642530216767245818997"
},
"signature_version": "v1"
}
]