LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tif_read.c:523:22.
{ "vanir_signatures": [ { "deprecated": false, "source": "https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018", "id": "CVE-2016-10270-21043118", "signature_version": "v1", "target": { "file": "libtiff/tif_strip.c", "function": "TIFFNumberOfStrips" }, "digest": { "length": 419.0, "function_hash": "217570062935108207213506467783707032506" }, "signature_type": "Function" }, { "deprecated": false, "source": "https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018", "id": "CVE-2016-10270-438ef051", "signature_version": "v1", "target": { "file": "libtiff/tif_dirread.c" }, "digest": { "line_hashes": [ "227979037930115295549200606344797044780", "304064853075978727773745147678512944439", "247178991344022167237135730424070535552", "281215183600724245730294442974530095132", "305164763526171681635348485961970663495", "178073106303980633009179021628806583257", "124692354437170973845498308911739901343", "114172573406440844168977052736038871039", "216187158007511905708691702014797602141", "2879496617748360527738794824120368194", "104995666070552702337610097727930891288", "115243487901340338471005043152426292490", "139147012495639512798477566459269828020", "105464633538825495977824827820924822994", "107723553272322545637638858690250870762", "290931200856179411197202820462678260933", "53478847736288984055319536672304171640", "47816606002615624330881726773444678337", "41175390837799653466983724778626736192", "71200253766754932186272388276437218414", "203193398437237192607582729440697709897", "70722196196013249240151454962309002082", "326510936351076789053991261527542020492", "272834617046870365591399382044184695558", "181871094969194701087817509287023198281", "254431987391002376872065047137279717069", "269526769066251921302003633010157440788", "202417575990367002590428723634683427130", "302339418109204909993807813573261863499" ], "threshold": 0.9 }, "signature_type": "Line" }, { "deprecated": false, "source": "https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018", "id": "CVE-2016-10270-b0b62bfc", "signature_version": "v1", "target": { "file": "libtiff/tif_dirread.c", "function": "ChopUpSingleUncompressedStrip" }, "digest": { "length": 1623.0, "function_hash": "202781527579831873861974969934754624663" }, "signature_type": "Function" }, { "deprecated": false, "source": "https://github.com/vadz/libtiff/commit/9a72a69e035ee70ff5c41541c8c61cd97990d018", "id": "CVE-2016-10270-c10031cd", "signature_version": "v1", "target": { "file": "libtiff/tif_strip.c" }, "digest": { "line_hashes": [ "251259821279157970787903007296993735349", "216789091117803774823384587008877918412", "335551065774136630098571473824439443675", "89261644350307141058375409406669172333", "102137725275466551305934319509417008195" ], "threshold": 0.9 }, "signature_type": "Line" } ] }